<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Jason Langridge's WebLog - MR Mobile! : Security</title><link>http://blogs.msdn.com/jasonlan/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en-GB</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Windows Mobile 6.1 gets Common Criteria Certification!</title><link>http://blogs.msdn.com/jasonlan/archive/2008/09/24/windows-mobile-6-1-gets-common-criteria-certification.aspx</link><pubDate>Wed, 24 Sep 2008 21:11:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8963934</guid><dc:creator>jasonlan</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/jasonlan/comments/8963934.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jasonlan/commentrss.aspx?PostID=8963934</wfw:commentRss><description>&lt;p&gt;I got some great news yesterday that Windows Mobile 6.1 has just gained Common Criteria Certification!&lt;/p&gt;
&lt;p&gt;If you aren't familiar with Common Criteria then &lt;a href="http://en.wikipedia.org/wiki/Common_Criteria"&gt;Wikipedia&lt;/a&gt; helps :)&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;The Common Criteria for Information Technology Security Evaluation (abbreviated as Common Criteria or CC) is an international standard (ISO/IEC 15408) for computer security.&lt;/p&gt;

  &lt;p&gt;Common Criteria is based upon a framework in which computer system users can specify their security requirements, vendors can then implement and/or make claims about the security attributes of their products, and testing laboratories can evaluate the products to determine if they actually meet the claims. In other words, Common Criteria provides assurance that the process of specification, implementation and evaluation of a computer security product has been conducted in a rigorous and standard manner&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Our team headed up by Jon Wall has been working really hard on this so it's great to see that it has now been announced!&lt;/p&gt;
&lt;p&gt;Microsoft Windows Mobile 6.1 completed evaluation to Common Criteria EAL 2 augmented with Flaw Remediation (ALC_FLR.1) in the AISEP on 7 August 2008.&lt;/p&gt;
&lt;p&gt;The Windows Mobile 6.1 evaluation builds on and extends the core security features of the Microsoft Windows Mobile 6 evaluation at EAL 2+.&lt;/p&gt;
&lt;p&gt;Further details about the scope of the evaluation can be found &lt;a href="http://www.dsd.gov.au/infosec/evaluation_services/epl/mobile_products/windows_mobile_v6.1.html"&gt;HERE&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8963934" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jasonlan/archive/tags/Windows+Mobile/default.aspx">Windows Mobile</category><category domain="http://blogs.msdn.com/jasonlan/archive/tags/Security/default.aspx">Security</category></item><item><title>Apple iPhone Security Hole</title><link>http://blogs.msdn.com/jasonlan/archive/2008/08/27/apple-iphone-security-hole.aspx</link><pubDate>Wed, 27 Aug 2008 23:17:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8901350</guid><dc:creator>jasonlan</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.msdn.com/jasonlan/comments/8901350.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jasonlan/commentrss.aspx?PostID=8901350</wfw:commentRss><description>&lt;p&gt;&lt;img src="http://blogs.msdn.com/blogfiles/jasonlan/200808272114.jpg" mce_src="http://blogs.msdn.com/blogfiles/jasonlan/200808272114.jpg" alt="200808272114.jpg" height="150" width="200"&gt;&lt;/p&gt;
&lt;p&gt;Wired Magazine have just discovered and shared a rather large security hole in the Apple iPhone.&lt;/p&gt;
&lt;p&gt;This essentially allows you to bypass the PIN security and gain access to the features of the device including the un-encrypted information stored on the device.&lt;/p&gt;
&lt;p&gt;To do this&lt;/p&gt;
&lt;p&gt;1. Tap emergency call.&lt;/p&gt;
&lt;p&gt;2. Double tap the home button.&lt;/p&gt;
&lt;p&gt;This drops you into the iPhones "favorites" section. From here you can make calls or send e-mail, and with a few steps you can browse to the Address Book and then on to Mail, Safari or the SMS application.&lt;/p&gt;
&lt;p&gt;You can read more details and a suggested workaround on the &lt;a href="http://blog.wired.com/gadgets/2008/08/massive-iphone.html" mce_href="http://blog.wired.com/gadgets/2008/08/massive-iphone.html"&gt;Wired Blog&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8901350" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jasonlan/archive/tags/Security/default.aspx">Security</category></item><item><title>Blackberry PDF Security Issue</title><link>http://blogs.msdn.com/jasonlan/archive/2008/07/19/blackberry-security-vulnerability.aspx</link><pubDate>Sat, 19 Jul 2008 09:56:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8753727</guid><dc:creator>jasonlan</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/jasonlan/comments/8753727.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jasonlan/commentrss.aspx?PostID=8753727</wfw:commentRss><description>&lt;P&gt;&lt;A href="http://news.zdnet.co.uk/security/0,1000000189,39448050,00.htm" mce_href="http://news.zdnet.co.uk/security/0,1000000189,39448050,00.htm"&gt;ZDNet&lt;/A&gt; has details of a recent Blackberry Security Vulnerability that allows an attacker to compromise the PDF attachment viewer service and allow that attacker using a specially crafted email to cause memory corruption or even execute code remotely on the attachment server...&lt;/P&gt;
&lt;P&gt;You can get more details from RIM &lt;A href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=KB15766&amp;amp;sliceId=SAL_Public&amp;amp;dialogID=75115505&amp;amp;stateId=0%200%2075117846" mce_href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=KB15766&amp;amp;sliceId=SAL_Public&amp;amp;dialogID=75115505&amp;amp;stateId=0%200%2075117846"&gt;HERE&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8753727" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jasonlan/archive/tags/Security/default.aspx">Security</category></item></channel></rss>