Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: Are there any pocketable Hardware Password Vaults

Subject: Re: Are there any pocketable Hardware Password Vaults
Date: Sat, 26 Nov 2005 14:47:08 -0500 (EST)
On Thu, 10 Nov 2005, felix.oxley@gmail.com wrote:

You could use your mobile phone.

1. It is protected by a PIN number
2. It could run a java encryption app to provide additional security.
3. It is always with you.
4. It can be accessed from your PC via Bluetooth or USB.
=====================

call me paranoid, but i see #4 as a liability, not an asset. i do NOT store "sensitive" information on anything with a wireless transceiver built in to it... remember paris hilton's address book? i wouldn't cry if my address book was lifted from my phone, but my paypal password...

regarding #1, a 4 digit PIN is *not* cryptographically secure. even if it did encrypt data (which it doesn't) instead of just "locking" it. unlocking data may take a few seconds; brute forcing a 4 digit PIN wouldn't take much longer.

on my palm pilot (with IR link disabled) i run STRIP <http://zetetic.net/solutions/strip/>. among other features, it's the best real-world OTP calculator i've ever used.

more stuff here - http://www.palmopensource.com/index.php3?category=31


-- ...atom

 _________________________________________
 PGP key - http://atom.smasher.org/pgp.txt
 762A 3B98 A3C3 96C9 C6B7 582A B88D 52E4 D9F5 7808
 -------------------------------------------------

        Bob Woodward:
                "How do you think history will regard the war in Iraq?"
        George "dubya" Bush:
                "It won't matter. We'll all be dead."


<Prev in Thread] Current Thread [Next in Thread>