PDA security with Windows CE

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS
Although there are numerous security threats associated with PDAs, the two biggest issues are viruses and the theft of sensitive data. At first, the thought of losing sensitive data or contracting a virus because of a PDA may seem ridiculous. However, both threats are very real, and I'll explain why. I'll also give you a few tips on constructing an effective PDA policy for your users. Viral infections
Before you send me an e-mail message, let me explain I'm well aware that there has never been a documented case of a virus attacking a PDA. This may be because the Windows CE operating system is so simple. When Windows CE was initially designed several years ago, the engineers at Microsoft stripped down the Windows 95 operating system to its core, added a few simple applets, and the finished product became Windows CE. There's a basic rule in computing that says that the more lines of code an application has, the greater the chance the application may be exploited. Because Windows CE was such a simplified operating system, many of the weaknesses that viruses could exploit in other operating systems simply didn't exist. As the years went on, the Windows CE operating system got a little more bloated, but it still lacks most of the features found in elaborate operating systems such as Windows XP. Because of this, virus attacks have never been an issue. Although viruses are not known to attack PDAs, a PDA can act as a carrier for a virus. For example, imagine that a user employs a PDA to check e-mail. Now suppose an e-mail message contains an attachment that's infected with a virus. If the user were to open the attachment, the virus would probably not infect the PDA. However, if the user were later to synchronize the file to a desktop PC and then open the file on the PC, an infection would occur. In this situation, the virus didn't harm the PDA, but the PDA was able to act as a carrier that allowed the virus to be put onto the network. Everyone in your organization who uses a PDA should be running antivirus software, just as they would on a laptop or desktop computer. There are two ways that this antivirus software works. One type of antivirus software stores an auto-protection file and a virus-definition file on the PDA so that virus scanning occurs automatically each time a file is accessed. Another breed of software stores the virus definitions on a network server. Because virus-definition files take up a lot of space that many PDA users simply don't have, storing them on a network server ensures that the definitions can be updated regularly. Any time the PDA user attaches to the network, the antivirus software automatically connects to the virus definition files and scans the PDA before any infections can occur. Compromised data
Whenever a PDA is lost or stolen, there's a risk that the data stored on the device could fall into the wrong hands. When I speak to IT managers about the data that could be compromised if a PDA were stolen, they almost always tell me that the PDAs don't need any real protection because there is no sensitive data on them. However, I feel there's actually quite a bit of sensitive data on the typical PDA. For example, suppose a VP at your company lost a PDA. Fortunately, this particular VP used the PDA as little more than an electronic organizer. So there's no sensitive information on the PDA, right? First of all, the executive probably has an appointment book or a calendar stored on the PDA. And how much sensitive information is stored within the calendar? If you're not sure, ask yourself what your competitor could learn by sneaking a look at the calendar, contact list, etc. Let's say that the executive in question never kept juicy information about top-secret meetings or customer contact information in his PDA. In fact, let's pretend that the PDA was brand new and for all practical purposes was empty. There is still useful information that could be gathered from the PDA. If your company uses a wireless network, someone could steal your company's SSID, channel, and WEP pass phrase from a PDA. Depending on the configuration, someone might even be able to obtain usernames, IP addresses, domain names, or even passwords. Most, if not all, of the information that someone would need to break into your company's network could be stored on the PDA, either in the form of data or as configuration information. I say it could be stored as data, potentially, because an alarming number of people store passwords and PINs on their PDAs. According to one statistic, one in four PDA users store PINs and passwords on their PDA -- but don't protect the PDA itself with a password. Personal PDAs vs. company-issued PDAs
So the real question now is what to do about all of the security threats that face your PDA users. The first thing that I recommend doing is supporting company-issued PDAs only. Although I like giving users as much personal freedom as possible, I strongly recommend banning privately owned PDAs. If employees really want to use their own personal PDAs, my philosophy is that you can't (and probably shouldn't) stop them from using them -- but you can prevent them from connecting them to your network. I'm opposed to privately owned PDAs being attached to the network because it's difficult for a company to control what it doesn't own. If a user owns a PDA, you really have no way of verifying that the user is running the appropriate antivirus software. Likewise, there's no way to really tell if an application installed by a user is legal or pirated. For your users who have company-issued PDAs, you should create a security policy that is fully documented so there are no questions of what will be expected from them. The policy will likely be very similar to the policy for your laptop users. For example, it should address things such as how often passwords should be changed, what applications are allowed, and what types of data may be stored on the PDA. In the following sections, I've outlined more detailed security recommendations that you might consider including as a part of your PDA security policy.

Talkback

Till last night I was believing Windows CE machines can't get viruses.

I was happily surfing - began at CEO Express.com then accessed a couple of newspapers, The Times, The Independant ... suddenly a pop up screen appears along the lines of:

"Would you like to download a program into the current application? If you do not answer "yes' your computer's performance may be below par". The choices were: Yes, No or 'close window'.

I tried 'close window' but nothing happened. I should probably have then done a re-set. Instead I clicked "No'. Immediately, a 2nd, 3rd, copy of the same pop up appeared.

Sometimes I could get one to disappear with the "no", but then two or three more would appeear. Eventually I did a reset & logged back online; into IE again and ... whoops, 1,2, 3 ... pop ups appear. Surfing the net is no longer practicable.

Is anyone out there familiar with this and can suggesty what I can do?

My machine is a H/PC, in fact an Intermec 6651, similar in spec to the MobilePro 790 (MIPS; running Windows for Handhelds 2000, Core System 3.0, IE 4.01).

Grateful any help!!!

ps: I've just posted a similar message on CE City (H/PC) site.

RJ99 in Saudi Arabia

T

via Facebook 7 March, 2004 11:19
Reply

I am looking for a PDA security applet that will function like "OnlyMe" only be compatible with a Palm OS or a Win CE platform. Know of any developers that do that?

You have display name. Display name where?

via Facebook 29 March, 2005 23:14
Reply

http://www.handango.com/PlatformProductDetail.jsp?siteId=1&jid=59X49332835D53229CF35XF49D35X578&platformId=1&N=96804&productId=174702&R=174702

via Facebook 23 November, 2005 08:01
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

2 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

7 hours ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

11 hours ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

15 hours ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

16 hours ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

18 hours ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

18 hours ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

20 hours ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

21 hours ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

22 hours ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

2 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

2 days ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

2 days ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Phil at Cloud4

This is unbeleivable government wastage with only one winner... Microsoft 1 - Tax payer Nil!

2 days ago by Phil at Cloud4 on 6 million wasted licences and £1,200 PCs: welcome to government IT
Mispam

So what do you do when you can't boot into windows? Why can't I just hold Shift while I power up instead of having to boot into windows and click a...

2 days ago by Mispam on Windows 8 start-up speed forces USB boot workaround
apexwm

I've also seen that Mac OS X for Intel machines is supposed to run in VirtualBox, which would also be a nice solution. I've never tried it though.

2 days ago by apexwm on xTreme Triple Booting: Linux, Mac & Windows