DPAPI Machine Key Security on Windows Mobile



Hi,

I am wondering if anyone knows how the DPAPI key management on Windows
Mobile works with the CRYPTPROTECT_LOCAL_MACHINE flag. How is the key
material is generated and stored?

The problem I'm trying to solve requires that I encrypt some data in a
file on a Windows Mobile 5 device, but the device may or may not be
password protected, so I'd like to use CryptProtectData with the
CRYPTPROTECT_LOCAL_MACHINE flag, but I can't find out anything about
how the machine key is derived, stored, etc.

It's OK if other processes running on the device are able to see and
decrypt the data, but we'd like to protect against forensic attacks.
For example, if a device were to be lost or stolen, would it be
possible for a hacker to remove the flash drive and retrieve enough
information from the physical device to decrypt the file?

Thanks,
Frank

.



Relevant Pages

  • Data Protection API Machine Key Security on Windows Mobile
    ... Mobile works with the CRYPTPROTECT_LOCAL_MACHINE flag. ... file on a Windows Mobile 5 device, but the device may or may not be ... decrypt the data, but we'd like to protect against forensic attacks. ...
    (microsoft.public.pocketpc.developer)
  • Re: Configuring RAM to 256MB on CEPC - Windows Mobile 5.0 ??
    ... The Mobile Windows 5 I installed on my PPC was not an OEM ... I was unaware that there was a platform tree form Win Mobile 5 for CE, ... o First Entry MUST be RAM, ...
    (microsoft.public.windowsce.platbuilder)
  • pocket-expert.de Newsletter #131
    ... Upgrade auf Windows Mobile 2003 Second Edition anbieten. ... Windows CE und Pocket PC aufgetaucht. ... Johnson, Autor des seit 25 Jahren erscheinenden kleinen Johnson, einem ...
    (microsoft.public.de.german.windowsce)
  • Re: AT&T Tilt coming?
    ... MORE AT&T TILT DETAILS ... Windows Mobile 6 Professional with Windows Vista ... Cellular Video -- watch streaming video on your device* ...
    (alt.cellular.cingular)
  • Re: develop for OE 6?
    ... This will be true for Vista as well, but the contact management is now part of Windows and separate from OE. ... But the bigger problem would be the programming hacks for the mobile device. ... Your best shot would seem to be to ask your questions in a developer newsgroup. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)