Security Best Practices - 8125, K-JAM, P4300, MDA Vario General

I'm embarrassed to ask this quesiton, but as I have basically my entire life on an MDA right now, as I plan of moving to the Wing I am forcing myself to implement sufficient secuirty in case the device becomes lost. What are poepl doing that is secure and the least intrusive?
thanks in advance

Use a good password (pref numbers and letters).
On WM6 use the encryption option to encrypt your SD card.

Related

Anti theft apps available?

I'm looking for an anti-theft app. I don't know if it exists yet.
Is there an equivalent to the symbian phone apps "Anti-thief" or "EzProtect"? It has some nice features to let your pda "phone home" when someone is tinkering with it, or you can remotely disable your pda by sending a password though sms.
I've been searching over the net and found "Kill-pda" but that can only erase the device completely by sms. Thats a bit overkill :lol:
I hope someone knows, because i learned the hard way that you really need an app like this. My phone got stolen once and I got a Huge A$$$ bill for calling to egypt en italy
edit: I found this description for EzProtect:
The application sends an SMS to your specified number as soon as the SIM card has been changed. By this way, you receive SMS on your friend's (or whoever's number u defined) cell with the thief's cellnumber and SIM number (IMSI) so it becomes very easy to track the thief.
I definately want an app that can do this. And I can imagine a lot of people wanting it too.
There was a discussion about this on HoFo in Oct ober when people first started receiving their Wizards. I think BTT (BeyondtheTech) mentioned something about it. I'll see if I can track it down this evening.
It certainly would be cool.
Check this out! http://www.ppcsg.com/index.php?s=0c0cedfa906ae1b85f844fb7b497def6&showtopic=65021
Hope this works. I have not tried this myself.
Thanks a lot for your help, but that was the program i mentioned in the threadstart "PDAKill".
The only thing it can do is erase the device completely when you send a sms to your pda containing a predifined password.
But when the thief takes out the simcard and puts in his own, then this program would be useless.
Guys, if I've seemed distracted for the last few days, this is why:
I've been working on a program called VJAccioPhone.
It is used to detect if your phone has been stolen and to permit remote use of the stolen phone. Your phone doesn't have to be stolen, eg if for some reason your wife is likely to discover your "niece's" affectionate messages to you, you can send a password protected remote keyword to format your phone and hardreset it. I'm sure you can think of better examples!
It's an expansion of some code I wrote for my unreleased plugin, VJEphemeris, which you can read about here. The release version allows you to do pretty much anything you can do with the phone when it's in your hand, all remotely. Destructive and constructive control.
This is a pre-announcement. I don't like preannouncing, but unfortunately this week I've been on a very limited programming quota due to the ministrations of my better half. So although the code is finally finished, it's being beta tested while I'm away on holiday. If all is well when I get back next week, hopefully I'll try to get it released!
Don't tell anyone else, but you can read about VJAccioPhone and see screenshots here. Please note, and don't ask, there is no download available at the moment.
V
Aside from that a program like this would be very handy, and I'm quite curious and will keep an eye on it myself, I advise everyone to activate the pin code on their simcard, and always call their mobile operator as soon as the phone is stolen so they can block your number to avoid getting high bills as the topicstarter said... You should also be able to get your number back easily by requesting a new sim card and having your mobile number set to that simcard again.
This may seem obvious to some people, but I just wanted to post it anyway since a lot of people are still not aware of these simple ways to protect yourself.
Absolutely true; in England, the police aren't interested in persuing phone theft, but for you own benefit, you must always have your IMEI blocked and the phone reported stolen immediately to prevent you being charged for calls.
VJAccioPhone will be able to report back to you even if the IMEI has been changed or it's being used abroad etc. It's more for protecting your data on the stolen phone then getting the phone back. Frankly, any thief would do better to throw the phone away then persue cracking strong protections. Stolen phones are easy enough to come by! However, at least a nice passer by might be able to get in touch with you!
V
Sounds great! Would it be possible to enable the phone ID (Where you can enter your name and contact details) thought this might be good if it was ever found (or part of the hard reset).
Wauw, this is great stuff Vijay!
If you need a beta-tester on the wizard platform, i would highly recommend myself
This would be excactly what everyone needs 8)
Would it be possible to save the configuration settings? Because my idea would be to include the cab file in my extended_rom, and thus make it install itself even after a hard reset. This would mean that the configurations settings also have to be loaded after the hard reset.
Keep up the great work Vijay
frigit: if you mean enable password screen, yes, should be no problem. however i'm thinking of writing a better custom password screen using some strong encryption, with optional destruction on failure.
leploep: of course, it's designed for extended rom etc. right now protection works as a ta k, for the demo, but i'll be writing protection into an invisible app. Remote control is already complete and works transparently when triggered, so the thief won't even realise what you're doing ie there's no sign of the control smss being received to the thief.
eg you can background call the police from the stolen phone
more when i'm back from holiday next week!
v
This is starting to sound like a killer app - pun intended 8)
I'm in for sure when you get this finished, Vijay!
Already finished for the demo version!
kept me quite busy, developing three intersecting programs, like playing chess! but they all seem to work ok. a friend is testing it hopefully this week then i'll see what i can do for wider release when i get back...
v
Well vijay555 , you can put me on the list of very interested persons on buying this soft.
Cheers mate.
vijay will this work on all the wm5.0 devices??
i.e. I have the pda2k with wm5.0 and have been looking for a prog like this since i got my device, also is it possible to keep this program after hard reset ?? as you know if a hard reset is done the data is gone, but the user now has an expensive device to start playing with
it's not been tested on wm5 at this time, actually because the guy testing has a wm2003 motorola - gulp! but everything i write is normally wm5 & wm2003 now. there is no reason why it's not wm5 compatible but i'll ensure it is before release. i can certainly say, to my pain, the hardReset keyword is very wm5, i activated it by accident in testing.
retaining it after hard reset is only possible, as far as i am aware, by using a custom ext rom or rom.i've not tried it on my magician or universal, but hopefully your device in particular ext rom customisation is possible. at this time it uses registry & normal exe/dll files to run, so no reason it can't be ext rom'med. hopefully this will be confirmed in testing shortly.
if anyone can think of any particularly useful remote keywords to incorporate drop me a line. as it is, the full version will permit remote .exe launching so it can do pretty much anything
v
a lot of us have paid an arm and leg for our devices so having that extra peace of mind,knowing that if your device is nicked your going to make it as hard as poss for the theif to try and profit from your loss.
vijay all the best mate so far your app looks very promising iv got the exec running WM05 so if you need a beta tester let me know LOL
and guys if you report your phone as lost make sure your service provider is also going to blacklist the device!
I work for Vodafones in a call centre in the birmingham, UK,but the amount of customer services that is outsoursed to other non vodafone call centres based here in the UK its unbelievable! the amount of complaints I deal with and customers accounts that I come across where the outsourced twats
will admin bar your sim card but not blacklist the handset!
anyway I'll keep my eyes open for any more theftbashing apps and will post on here.
N2h said:
I work for Vodafones i
Click to expand...
Click to collapse
But have an O2 phone.....
Whow V.
Looks very very promising.. !
Great Job man :!:
i'd be happy to check it on my devices :wink:
Cheerz
lol mcwarre
even with our staff accounts we can't get the pdas as they are only available for busniess customers to be honest with you don't know why vodafone is stupid enough not to sell to normal consumers its the biggest network in the uk,
the staff phones we do get we gets 12 months line rental free lol
annnnd from all the universals I think the exec with its black shell looks the most stunning-the white shell devices just look a tad bulkier! lol

Security, esp. SD-Card encryption

Anyone know of good security products? I am not all too concerned about "switch-on" and login type protection, but rather a good and hard transparent SD-Card encryption. Is there any product or freeware (maybe a bit like truecrypt) out there?
have a look here and see if any suits your needs
http://www.handango.com/SoftwareCat...Ntk=All&siteId=1&N=96806&Nty=1&addDevices=add

How to use SD card as real Secure card?

Hi!
Could someone point me to info how can I use SD card as real Secure storage of data?
What I need to do - to use it under Win Mobile platform?
is Any 3-rd part software available?
thanks for any information.
ryhor said:
Hi!
Could someone point me to info how can I use SD card as real Secure storage of data?
.
Click to expand...
Click to collapse
I guess it depends on how you define secure?
If you mean 'nobody else can access the data if they get a hold of the card' ... there are many articles on the web discussing this issue - here's a decent (but slightly dated) one: http://www.windowsecurity.com/articles/Securing-Pocket-PC.html
There are a LOT of app's which will provide you with varying levels of encryption for your data - Resco Explorer has an option to encrypt, for example.
Use google (or your preferred search engine) to search for "pocket pc" and "security" (or perhaps "encryption") and you'll get plenty of hits.
I must point out though that we are talking about an extremely portable device. A PDA is just so easy to steal! An SD card is even more so. So if you are talking about data which really MUST remain secure ... you may well be better served by not putting it on your unit in the first place.
Hi
Actually we wanna do a simple thing.
we wanna put our application and data on SD card and allow access to this storage only to someone who have right to do it. (it isn't top secret )
SD category 3 of levels of SDMI security requirements will be fine for us.
http://www.sandisk.com/Oem/DocumentInfo.aspx?DocumentID=1344
But as I understand - there is some problem with it. It is a little bit strange - because every normal SD card has to provide this feature (and it is), but just there is no any suuport of it from OS? even there is no some 3-rd part File System Drivers?
It isn't sounds so hard to implement.
Why do I feel like we got gipped again?
I believe SD is a scam over MMC cards just like 1.44MB 3.5" floppy disks was a scam over the 720KB version... :x
SDMI
ryhor said:
Hi
But as I understand - there is some problem with it. It is a little bit strange - because every normal SD card has to provide this feature (and it is), but just there is no any suuport of it from OS? even there is no some 3-rd part File System Drivers?
Click to expand...
Click to collapse
I did some research into SDMI last year, as a part of a contract I was on. I've dug into my notes and found this:
http://www.microsoft.com/windows/windowsmedia/drm/sdksandversions.aspx#version
It may be of some use to you. Probably not ... frankly I find the whole approach of DRM to be a joke

eWallet vs CodeWallet Pro

Thinking of getting one of these, any one here have experience of these two apps and any recommendations ?
Thanks.
Hello,
Actually I have pretty much experience with CodeWallet, eWallet and FlexWallet. I've been using eWallet for many years and recently switched to CodeWallet. There is a serious security issue with eWallet. It appears the Category names are in plain text unencrypted format !! Altought the actual cards are encrypted, I wouldn't be so happy for a thief to be able to see what I am hiding inside (i.e. Bank Accounts etc..) Sometimes the category name itself is something you would want to protect. That's why I switched over to CodeWallet even though CodeWallet provides only 128 bit encrptiong while eWallet provides 256 bit, though again with no category encryption.
MOBILER
Thanks for pointing that out.
I agree with you , eWallet is now off my list.
The other option I am looking at is instead getting Sentry 2020 which creates an encrypted mount. Then just have my sensitive info in Excel spreadsheets on that mount encrypted. Perhaps the encrypted mount can be my external storage card.
http://www.softwinter.com/sentry_ce.html
http://www.geek.com/hwswrev/wince/sentry/index.htm
Any opinions on this ?
Gut feeling , CodeWallet seems best all rounder so far.
hey linuxgeek
from my own personal experience, I've used many encryption programs and found all to have flaws except for this one: CryptoStroage which I eventually purchased.
It's key benefits is unlimited size - most other programs have limits of a few Mbs. with this program I can mount a few houndred MB volume on my SD Card where I put all my scanned documents in and view them with acrobat reader.
Another key benefit it has a desktop version so you could use the same volume to mount on your desktop pc. very neat, instead of going to the ppc each time. It is the most fast I've tested and is super easy to use. It looks like another SD card storage.
I think I've tested Sentry 2020 and found it was inconvenient for me.. but i'm not sure.. I may have not tested the recent version so I don't know. but I see Sentry costs $50 and Cryptostorage costs $20.
Let me know if there's something else i can help you with.
Great tip thanks for that.
Cryptostorage looks fab , definately going to get it.
Do you think its worth getting CodeWallet also or shall I just get Cryptostorage and like metioned earlier keep all my info in excel/word files inside the safe ?
Thanks for all your input.
Looking at Cryptostorage website it doesn't mention it works with Windows Mobile 5 .
Are you or any one using on a Universal with WM5 ?
LinuxGeek said:
Looking at Cryptostorage website it doesn't mention it works with Windows Mobile 5 .
Are you or any one using on a Universal with WM5 ?
Click to expand...
Click to collapse
Hey,
Yes it works on my Universal just fine. I found it to be the most convenient program among the encryption programs.
I do suggest getting Codewallet as well. It is not convenient to mount a volume each time, then fire up excel if only to check for a password. I personally have all my passwords, maybe a hundred stored with Codewallet and I also enjoy the Desktop version, which is easier to use when working on the desktop PC. I use my wallet file on the Synced My Document folder and then the desktop version and the PDA version are synced with the latest wallet file each time.
Thanks for reply.
I am moving towards getting eWallet and using cryptic category names because of its 256bit encryption.
I am definately going to get Cryptostorage too now that u confirm it is fine under Universal.
Thanks for all your input mate.
Anyone used cryptocard? I've been thinking of changing from myCodes Lite to this. myCodes seems OK but is a little slow.
Anyone ever wondered, how comes that CodeWallet can sync your Desktop/Mobile wallet without any password entered?
I guess they encrypt the data by record and keep a timestamp unencrypted. But this way if you often use the same login name and have many similar forms (Username, Login, URL), an attacker could get the password somehow, I think, since there is always the same beginning of the records.
It's something like security vs. sync-without-password-prompt. Where as 128bit RC4 isn't "strong" encryption nowadays anyways. I'm a bit concerned about the *real* security of this app...
Cheers,
-mARKUS
CodeWallet insecure
CodeWallet now is a NO GO for me. Found some patched EXE-file of its Desktop-version, where you can enter *any* 3-digit password to open your file. This is not security, this is INsecurity par excellence.
Cheers,
-mARKUS
UPDATE:
- Windows Mobile Security Software fails the test (info about header-copy to open files)
- mininova (first mention of this security flaw)
- PxDxA (detailed infos about this flaw)

Anti theft solution

Can anybody advise to the best program for anti-theft solution for the TyTN working on WM5?
My requirement are:
1, It launches from ext-rom sothat it survives hard resets. Please note that if it's not certified it will not install from ext-rom on WM5.
2, It will send a sms to a predefined number without letting the thief know. This will be done: A, when a new sim is inserted. B, If the device owners identity is changed or deleted.
try IIWPO with the "unsigned Hack" before (read it somewhere here on the board)
I'll try to use the same @ my next Hardreset - will report here when done...
found the link
put Default_Signed_DisableSecurity.CAB from this thread in ext_Rom to be installed first of all
Lio said:
Can anybody advise to the best program for anti-theft solution for the TyTN working on WM5?
My requirement are:
1, It launches from ext-rom sothat it survives hard resets. Please note that if it's not certified it will not install from ext-rom on WM5.
2, It will send a sms to a predefined number without letting the thief know. This will be done: A, when a new sim is inserted. B, If the device owners identity is changed or deleted.
Click to expand...
Click to collapse
The anti-theft app can only go so far as much as how well the thief knows about WM devices, as far as WM devices is concern, a flash of a ROM will wipe everything, I mean EVERYTHING!
So it doesn't matter where you put the anti-theft app start-up, the best bet is only that wishing the thief doesn't really know anything about WM devices.
My opinion goes like this after a number of tries on different brands of these anti-theft app with or without GPS functionality, as long as the pick-up / thief swap the SIM, the device should simply lock and with some info for the pick-up / thief to return to (basically you), any attempts of breaching that level should be a total wipe-out of the whole thing including the SD card itself.
However, as I said, if the pick-up / thief deliberately flash your device with a ROM before using it, nothing will work, because if the pick-up / thief knows about hard-resetting your device to get away from anything, he / she might as well know about flashing a ROM is the best way afterall, as there are so many info about this skill posted on this forum, I do not see it as any kind of high-level skill set at all.

Categories

Resources