Re: OTF Encryption? Basic PPC2003 se security questions? (newbie)

From: Roger Parks (CompletelybogusAddress_at_Privacy.net)
Date: 12/29/04


Date: Wed, 29 Dec 2004 01:58:27 +0100 (CET)

THANK YOU for your response!!

> Beverly Howard [Ms-MVP/MobileDev] wrote:
> in general... there are no current ppc exploit threats... the ppc is a
> client only, which deals with most exploit methods... there have been
> some "proof of concept" exploits, but no known current threats to
> default installs.

Good to know.

The concern here would be coming across one of those "overflow/arbitrary
code" exploits that gets I.E 6+ even though ActiveX is disabled. Or, I
suppose, an active daemon (com?) is attacked.

>
> os is in rom, but called from ram space... complicated, but "half true"
> since rom files can be displaced by replacement files.

This suggests that the loader looks at a "replacement" folder before
loading in a file from rom? e.g. a dated "ms.dll" in rom would be
replaced at load time by an updated "ms.dll"? What is the name of that
folder (or is it specified in some .ini or registry key?)

>
> added programs can be loaded into ram or memory cards, and are loaded
> into "program memory" (start/settings/system/memory)
>
> There are some third party encryption packages.
>
> However, the device "password" is very secure with respect to anything
> in ram (not on memory cards or "safe storage") It increases intervals
> between attempts and the only way to recover from a lost password is to
> hard reset the device which erases all ram content.

Excellent!!

And "safe storage" is non-volatile memory!? So a hard-reset erasure is
an active action!?

If so, then someone could - hypothetically - physically remove the
"safe-storage" memory and then read it!?

And if so, then an encryption program that decrypts from one file in
safe-storage to another would be undesirable; whereas on that decrypts
"on the fly" into execution memory would be better!?

(sorry 'bout the questions; a friend experienced identity theft :-(

>
> "power down" does not erase ram... it simply puts the device into
> "suspend" mode.

Heh...... learned that this afternoon when I powered up and there was my
last program open and ready to continue :-)

however, afaik, there is no way to extract ram data

> such as using a hex editor.
>
> Happy Holidays,
> Beverly Howard [MS MVP-Mobile Devices]

THANK YOU again!!



Relevant Pages

  • Re: Difference between ROM and RAM
    ... to configure their memory the way they want would be good. ... Finally, if you code for a requirement of 128MB of RAM, you'll really limit ... RAM and ROM up until ... I'm programming application for Pocket PC and I'm ...
    (microsoft.public.pocketpc)
  • Re: AES and dynamic table generation
    ... >> multithreaded, portable applications. ... > A microcontroller with little ROM and plenty of RAM? ... where the only memory available is stack based RAM. ...
    (sci.crypt)
  • Re: CP/M-85 ??
    ... The basic answer still stands, 8085 runs CP/M, yes. ... M10x have 32k of rom at 0000. ... That's not an advantagous memory map ... All the extended mapped ram in the world makes only for a ramdisk. ...
    (comp.os.cpm)
  • Re: clientaz.dll
    ... Having my first computer for 2 months now, I don't know much about RAM and ... ROM other than - the more, ... program, I interpret it saying that I need more RAM! ... At the top of the screen it said: RAM Usage 99%, Virtual Memory Usage ...
    (microsoft.public.security.virus)
  • Re: HP Warranty
    ... I replaced the bad Ram with Memory from Crucial and everything is working ... is not a customer replacement item. ... have to send the computer in as RAM was not a customer replacement ...
    (comp.sys.hp.hardware)