news | articles | reviews | software | modules | accessories | discussion | faq | mobile | store
VisorCentral.com >> Discussion >> Visor Related >> How To / Troubleshooting
built in security or other addons ?

Post a New Thread | Post A Reply

  Last Thread   Next Thread
Author
Topic: built in security or other addons ?    
gary ng
Member

Registered: Feb 2000
Location:
Posts: 8

Post

Hi,

Just got my Visor Deluxe. Wondering if the built-in security feature is good enough or I should get one of those encryption programs ? And if I really should opt for one of those addon, which one would people recommend ? Well, I would just like to store things like password, PIN etc.

Thanks in advance.

gary ng is offline Old Post 02-09-2000 12:17 PM
Click Here to See the Profile for gary ng Edit/Delete Message Reply w/Quote
ragamuffinn
Member

Registered: Oct 1999
Location: Mililani, HI, USA
Posts: 256

Post

If you use the built-in security alone, it isn't likely that someone will have the opportunity to get to your passwords if your Visor gets stolen. A more reasonable concern is the vulnerability of the data on the computer you hotsync to. If you sync at a computer that you do not have complete control over--particularly in an office environment--or even if your computer at home gets stolen, someone may have the opportunity to view the hotsynced files with a hex editor, and the "hidden" records belonging to the default apps will no longer be so hidden. So just in case, I think it's a good idea to use encryption software for your passwords.

Some encryption apps are intended to work as memopads and are thus quite versatile. Others are made specifically for account passwords and come with predefined fields. I don't use the former, but I do use the latter. A good one, IMO, is STRIP. You can get a version with 128-bit, IDEA encryption. It's also FREE! Another one I've tried, Multiaccounts, has a slightly better interface, but has a proprietary encryption scheme that is not as strong as IDEA, and it's shareware.

Some have conduits and desktop applications to make data entry easier. One is TopSecret. It's closer to the memopad type, and comes with 128-bit encryption (TINY, I think). It's also shareware.

[This message has been edited by ragamuffinn (edited 02-09-2000).]

ragamuffinn is offline Old Post 02-09-2000 01:50 PM
Click Here to See the Profile for ragamuffinn Edit/Delete Message Reply w/Quote
Winchell
Member

Registered: Oct 1999
Location: Baltimore MD, USA
Posts: 717

Cool

And keep in mind that the built in security does absolutely nothing if you fail to set the security app to "hide private" each and every time you turn your Visor off.

I'm using a hack called Secure Hack which automatically hides private docs at power off.

Winchell is offline Old Post 02-09-2000 05:44 PM
Click Here to See the Profile for Winchell Edit/Delete Message Reply w/Quote
bregent
Member

Registered: Dec 1999
Location:
Posts: 170

Post

I agree, Strip is great and you can't beat the price. But I ended up going with CryptInfo because I liked the interface better. I create new accounts a lot and just found CryptInfo easier to use. I also liked the fact that I could import my already existing 50 accounts into it. Maybe Strip can do this now? CryptInfo is not cheap at $12.95, but to me it was worth the registration price.

Whatever you do, don't rely on the Palm's security to store sensitive account information.

bregent is offline Old Post 02-09-2000 06:39 PM
Click Here to See the Profile for bregent Edit/Delete Message Reply w/Quote
frasej
Member

Registered: Dec 1999
Location:
Posts: 103

Post

You might also look at SecureMemo from Certicom. It's a free replacement for the MemoPad, but it will encrypt any memo you like.

------------------
Jay

frasej is offline Old Post 02-09-2000 10:03 PM
Click Here to See the Profile for frasej Edit/Delete Message Reply w/Quote
yucca
Member

Registered: Jan 2000
Location:
Posts: 434

Thumbs down

I have previously posted my heretical views re: Palm security ( http://discussion.visorcentral.com/...TML/000298.html), and I still haven't seen anything that convinces me that a Visor is a good place for sensitive information.

Even if I used encryption software, I would not presume that a misplaced or stolen Visor's data was secure. However, if you keep sensitive information on a desktop machine, that is indeed already your weakest link (especialy if it is running Win9x).

Don't forget, checking and savings accounts do not have theft/fraud protection like that of a credit card account. If the access informaiton to your checking and savings accounts is compromised, you could lose everything in them.

Furthermore, for the purposes that you are proposing, I'm down on encryption software (desktop or Palm) because a single strong password is going to be harder for you to remember than the number of PINs that most people need to know.

That said, there is always the need to secure non-sensitive private information in a manner that keeps honest folk honest. The built-in security, with something like Padlock Plus (a Hack), is fine for this purpose.

[This message has been edited by yucca (edited 02-09-2000).]

yucca is offline Old Post 02-10-2000 02:24 AM
Click Here to See the Profile for yucca Edit/Delete Message Reply w/Quote
gary ng
Member

Registered: Feb 2000
Location:
Posts: 8

Post

Thank you all for the suggestion and information. I kept my sensitive information on a PC currently on a PGP encrypted drive(triple DES) and those hotsync data will also be on this drive only. What I don't know is how vulnerable Palm OS is say for people to get physical access to my visor and load some hack/apps to grab those information stored in it. Judging from the response, it seems that the built-in security is very much like what one have on Windows 95/98/NT which is a form of access control but the underlying content is in clear text format. If that is the case, I believe I really need some kind of encryption program to make sure the data itself is protected.

gary ng is offline Old Post 02-10-2000 02:52 AM
Click Here to See the Profile for gary ng Edit/Delete Message Reply w/Quote
bregent1
Member

Registered: Dec 1999
Location:
Posts: 74

Post

yucca,

You're certainly not alone in your views. But I feel that while not perfect, encrypting sensitive data will at least slow down unauthorized account access until I have time to change my account passwords. Of course there's no guarantee but I feel it's a worthwhile risk. Also, could you please explain what you meant in the statement below? Thanks.


quote:
Originally posted by yucca:
Furthermore, for the purposes that you
are proposing, I'm down on encryption software (desktop or Palm) because a single strong password is going to be harder for you to remember than the number of PINs that most people need to know.



bregent1 is offline Old Post 02-10-2000 06:39 AM
Click Here to See the Profile for bregent1 Edit/Delete Message Reply w/Quote
bregent1
Member

Registered: Dec 1999
Location:
Posts: 74

Post

yucca,

You're certainly not alone in your views. But I feel that while not perfect, encrypting sensitive data will at least slow down unauthorized account access until I have time to change my account passwords. Of course there's no guarantee but I feel it's a worthwhile risk. Also, could you please explain what you meant in the statement below? Thanks.


quote:
Originally posted by yucca:
Furthermore, for the purposes that you
are proposing, I'm down on encryption software (desktop or Palm) because a single strong password is going to be harder for you to remember than the number of PINs that most people need to know.



bregent1 is offline Old Post 02-10-2000 06:40 AM
Click Here to See the Profile for bregent1 Edit/Delete Message Reply w/Quote
yucca
Member

Registered: Jan 2000
Location:
Posts: 434

Arrow

Passwords are the weakest link in most security systems because people make them too easy to guess. If an attacker can guess your password or crack it with a dictionary program (or other cracking utility), then even a trillion bit encryption key won't protect your data.

There are many sources of information on this topic. One that I have on hand is:
http://consult.cern.ch/writeup/security/security_3.html

There is a science to determining the minimum length of your password (or pass phrase), so that it matches the level of encryption you are using (sorry - don't have any references available at the moment). Choosing a good pass phrase is a skill that most folks are just not willing to cultivate; never mind taking the effort to memorize the result - - and it was this last observation that was the inspiration for my comment that aroused your curiosity.

I'm guessing that most folks have two or three PINs to remember, for a total of 8 or 12 characters. A good passphrase for a 128 bit key should be more that 16 characters in length (if memory serves). See the problem?

BTW, your approach makes sense. Unfortunately, I'm afraid that too many folks are blindly placing their trust in software, when alittle exercise of wetware is the better solution . . .

[This message has been edited by yucca (edited 02-10-2000).]

yucca is offline Old Post 02-10-2000 08:34 AM
Click Here to See the Profile for yucca Edit/Delete Message Reply w/Quote
All times are GMT. The time now is 02:26 AM. Post New Thread    Post A Reply
  Last Thread   Next Thread
[ Show a Printable Version | Email This Page to Someone! | Receive updates to this thread ]

Forum Jump:

Powered by: vBulletin Version 2.3.4
Copyright ©2000, 2001, Jelsoft Enterprises Limited.