|
From: Florin A. <fl...@sg...> - 2003-10-27 19:43:06
|
On Fri, 2003-10-24 at 02:32, Jochen Hoenicke wrote: > > On Thursday 23 October 2003 20:47, Florin Andrei wrote: > > In any case, a palmtop is never to be considered totally secure, but i > > feel that, if the encryption stuff doesn't have any inherent flaws, the > > security of the hardware should be better than that of the PCs (it's a > > lot harder to install "keystroke loggers", it's a lot harder to snoop on > > the RF fields generated by the display and by the input device, etc.). > > It's probably as easy to build a keystroke logger for a Palm as is for a > PC. Ummm... you're thinking about software-based ones? Yeah, those should be quite simple to implement. I was actually thinking of hardware-based keystroke loggers, not software ones. The PC-based hardware loggers can be bought on the Internet, are fairly popular, and can be installed in a matter of seconds. Those are very nasty things. But a Palm-based hardware logger should not be common knowledge, if it exists at all, and should be a lot harder to install. Not impossible, just harder. > On the other hand you don't install new programs > from unknown sources as often on your Handheld as you do on your PC > and the PC is often used by more than one person. Yeap, the PDA is more "isolated" than a PC. This might change, though, with the emergence of the PDA-cellphones that are Internet-enabled. One can envision, in a not-too-distant future, a time when a PDA-shaped device will do PDA stuff, cellphone stuff, will be more or less permanently on-line, and it will actually be a portable (wearable) PC and music player and TV set and whatnot. Then the isolation advantage will vanish. But for the moment, at least, a PDA looks much better than a PC from a security perspective. If the Keyring master password is good (long and complicated), and if the encryption used by the application is strong and free of flaws, the only ways for someone to break into a PDA crypto-vault are: 1. Steal the PDA, install a Grafitti logger, put the PDA back, wait for the owner to enter the password once, then steal it again. This is very difficult. It might be easy for a close relative or a "friend" to do it, but not quite so easy for a total stranger. Especially since there's a hard rule that should be observed by anyone who uses computer- or PDA-based crypto-vaults: if your device got stolen and you recover it, do a full and paranoid cleanup and then reinstall from backups before doing anything else. That, in addition to a thorough hardware "debugging" (literally). That assumes that the backups are clean, which leads us to the next item... 2. Break into the PC that has the PDA backups, and bug the backups with a Grafitti logger. Wait for the owner to sync the PDA a second time, then break into the PC again and steal the logs. This may or may not be easier than stealing the actual PDA. 3. Over-the-shoulder password-snooping. Keyring, fortunately, can veil the password. It's a difficult to use feature if the password is strong (long and complicated) but worth the trouble. Sure, the Grafitti gestures themselves can be snooped on (or recorded on a video camera for later analysis) but, hey, nothing's perfect. I'm not sure if these things are mentioned anywhere in the Keyring's documentation. If they're not, perhaps it's a good thing, IMHO, to add them to the user's guide or something like that. Like, tips to secure your crypto-vault, or something. This mailinglist thread already has some good stuff on this topic. Users should be aware of overall security issues. Strong crypto is good, but sometimes it creates a false sense of security. -- Florin Andrei http://florin.myip.org/ |