Windows Phone Thoughts - Daily News, Views, Rants and Raves

Check out the hottest Windows Mobile devices at our Expansys store!


Digital Home Thoughts

Loading feed...

Laptop Thoughts

Loading feed...

Android Thoughts

Loading feed...




Go Back   Thoughts Media Forums > WINDOWS PHONE THOUGHTS > Windows Phone Software

Reply
 
Thread Tools Display Modes
  #1  
Old 05-25-2006, 01:27 AM
Jon Westfall
Executive Editor, Android Thoughts
Jon Westfall's Avatar
Join Date: Aug 2006
Posts: 3,233
Default Subsembly Wallet Released

http://subsembly.com/en/wallet.html

"Subsembly� Wallet is an extremely secure password and data safe application. Stored passwords and confidential data are protected by state-of-the-art 256 bit AES encryption technology. Subsembly Wallet Pocket is optimized for use in mobile environments by providing convenient one-handed access according to the new Windows Mobile 5.0 user interface style."



Subsembly, the newest addition to the pocket pc wallet application genre, is now available, supporting variable encryption levels, so you can be paranoid, somewhat paranoid, and ultra paranoid about your data (Or use a higher encryption level if your company requires). They have a 30 day trial, and are offering a 50% off coupon to Thoughts readers, simply use 2C3EE385 when ordering from Handango [Affiliate]!
__________________
Dr. Jon Westfall, MCSE, MS-MVP
Executive Editor - Android Thoughts
News Editor - Windows Phone Thoughts

 
Reply With Quote
  #2  
Old 05-25-2006, 09:04 AM
subsembly
Neophyte
Join Date: Oct 2005
Posts: 8

Hi,

I have one important note to add: The coupon code is only valid through 31st of May!
 
Reply With Quote
  #3  
Old 05-25-2006, 10:21 AM
pheral
Ponderer
Join Date: Apr 2006
Posts: 76

Ooh, this is nice timing. I was looking for something to compare with eWallet, and FlexWallet failed to install on my device... so now i can use this as an alternative. Looks like i might prefer the layout too.

(edit: bears mentioning alex has been in touch about flexwallet after reading this, which is just really cool. i'm loving the interest pda-software developers show in users! very different from standard commercial cust service)
 
Reply With Quote
  #4  
Old 05-25-2006, 10:55 AM
Ce
Ponderer
Join Date: Jun 2002
Posts: 61

I know that secure storage of your data is the most important part of programs like these. But it just doesn't look nice on a VGA screen....blurry icons and parts of the screen.
 
Reply With Quote
  #5  
Old 05-25-2006, 01:05 PM
drummrsanonymous
Pupil
Join Date: Jan 2005
Posts: 33
Send a message via AIM to drummrsanonymous

Anyone know if this wallet will lock out the wallet file after so many failed password attempts? I can't find anything about that on the info page, so my fear is no.

I guess I'll keep searching for a wallet that will lock out a wallet until the next sync. Until then I'll be too paranoid about loosing my device and someone guessing their way into the wallet.
 
Reply With Quote
  #6  
Old 05-25-2006, 02:50 PM
joker
Banned
Join Date: Oct 2005
Posts: 64

codewallet has this since..what the heck i know
 
Reply With Quote
  #7  
Old 05-25-2006, 05:11 PM
subsembly
Neophyte
Join Date: Oct 2005
Posts: 8

You are right, there is currently no limit on the number of password tries when opening the wallet. If there is popular demand for such a feature I will add it in the next minor release (free update). What would you suggest that the application should do when all password attempts have been used up without success?

However, for the sake of security one should always choose a password that cannot be guessed. Therefore, when creating the wallet the application provides an indication about the strength of the password chosen.

Also, a software implemented counter to restrict the number of password attempts, can always be forged through some re-enginering. A really destined hacker attempting to crack the wallet encryption will always do so through some special application, ignoring any such counter completely. So it actually gives you a false sense of security.
 
Reply With Quote
  #8  
Old 05-30-2006, 08:34 PM
drummrsanonymous
Pupil
Join Date: Jan 2005
Posts: 33
Send a message via AIM to drummrsanonymous

Quote:
Originally Posted by subsembly
What would you suggest that the application should do when all password attempts have been used up without success?
I know there are probably technical limitations on what can feisably be done, but placing a software lock on the file could work. The lock would be opened on next desktop sync and/or after so many minutes. The number of minutes would be user-defined and could be turned off so that only a sync will unlock it.

Quote:
Originally Posted by subsembly
However, for the sake of security one should always choose a password that cannot be guessed.
Obviously. I'm always conflicted though over having a really strong password and having quick access to the info I need frequently. I guess folder/card-level passwords would be a way around that.

Quote:
Originally Posted by subsembly
Also, a software implemented counter to restrict the number of password attempts, can always be forged through some re-enginering. A really destined hacker attempting to crack the wallet encryption will always do so through some special application, ignoring any such counter completely. So it actually gives you a false sense of security.
I hadn't thought about using a standalone app to crack the file. However I think the lock would provide a bit of a barrier to less-determined theives/hackers/finders/etc.
Maybe instead of just a lock it could overwrite the file with random bits. Don't know how possible that is though. Plus the file would still be available to determined hackers before they might try to guess the password.
 
Reply With Quote
  #9  
Old 05-31-2006, 06:56 AM
subsembly
Neophyte
Join Date: Oct 2005
Posts: 8

Hi,

I guess locking the file for some amount of time is probably the best idea. Because it is only the manual password entry attempts that can be locked out, anyway. Requiring a sync on the other hand may be a problem if you are using your Pocket PC on a longer travel, or you have a Mac to sync with.

Currently folder/card-level passwords are not supported, but you could easily create multiple Wallet files with different encryption and passwords.

Overwriting the file would be possible. But due to the way a mechanism called "wear levelling" is used with flash memory, any new data that is written to memory is internally written to a new location. Hence the data will still be physically present in the flash memory. Although I am not sure how to get access to it.

I like the idea of locking the user out for just a couple of minutes. I guess I will add this feature in the next minor release, due for end of July. As usual with my software the minor release will be a free update. Thanks for your input!
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 08:11 PM.