BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 06-24-2009, 05:49 AM   #1
Brendan42
Thumbs Must Hurt
 
Brendan42's Avatar
 
Join Date: Mar 2006
Location: London
Model: 8900
Carrier: If I had a choice, a man-bag like Jack on Day-6.
Posts: 165
Default Content Encryption advice/comment please

Please Login to Remove!

To everyone who has enabled Content Encryption on their BES:

We are about to have this forced upon us by our USA head-office. As we are in control of our BES, we'd like to weigh up pros and cons first. Any help on the following questions will be appreciated:
1) Any suggested policy settings? WE're not planning on encrypting the SD cards, but open to suggestions. Possibly include some of the policy setting you have implemented so far.
2) Device performance. We still have quite a few older devices, from 6230 to 7100, 7290 to newer 8100, 8800, 8900, 9000. Any performance issues with the older ones?
3) Any negative comments regarding encryption welcome. Would help us assess a worse-case scenario
__________________
___________________________________________
Better to light a candle than to curse the darkness.
Offline  
Old 06-24-2009, 08:03 AM   #2
hdawg
BlackBerry Genius
 
hdawg's Avatar
 
Join Date: Aug 2006
Model: hdawg
PIN: port3101.org
Carrier: hdawg
Posts: 6,632
Default

First off ... I'm sorry. Unless your USA office is under some government regulation I'd be surprised if they had a good reason for enabling this; in general it is overkill.

Personally I'd stick with a good password policy and some user education. Anything before the 8xxx series is horrible with content protection, and even the 8xxx series isn't really all the glorious with it. 9xxx is ok, 82xx is so so, and 8900 is a little better than the 82xx.

Worst case scenario:

1) Users complain that the devices are horribly slow
2) When you wipe a device it does a full memory scrub expect it to take an hour ... instead of the standard 5 minutes without content protection enabled.

I'd highly recommend you start with a pilot group of users that is patient... plus what is the point of enabling content protection on the devices and not encrypting SD? Someone can copy data to that card ... and then you've busted the whole security model.
Offline  
Old 06-25-2009, 04:47 AM   #3
Brendan42
Thumbs Must Hurt
 
Brendan42's Avatar
 
Join Date: Mar 2006
Location: London
Model: 8900
Carrier: If I had a choice, a man-bag like Jack on Day-6.
Posts: 165
Default

Thanks hdawg. We're trying to fight back on this issue, just not sure for how long.
Reading your log-analysis blog with great interest. About time someone shed some light on this.
__________________
___________________________________________
Better to light a candle than to curse the darkness.
Offline  
Old 06-25-2009, 08:09 AM   #4
cgprelude
Knows Where the Search Button Is
 
Join Date: Aug 2006
Location: DC
Model: 8800
Carrier: AT&T
Posts: 38
Default

Yes the scrubbing feature is terrible. Our security department likes to all enable this feature. Then when I need to wipe their devices and it starts scrubbing I just say OK bring it back tomorrow when its done so I can finish working on it. It's ridiculous...
Offline  
Old 06-25-2009, 09:59 AM   #5
hdawg
BlackBerry Genius
 
hdawg's Avatar
 
Join Date: Aug 2006
Model: hdawg
PIN: port3101.org
Carrier: hdawg
Posts: 6,632
Default

Quote:
Originally Posted by Brendan42 View Post
Thanks hdawg. We're trying to fight back on this issue, just not sure for how long.
Reading your log-analysis blog with great interest. About time someone shed some light on this.
Keep fighting the good fight ... your end users will appreciate you.

... and thanks for reading
Offline  
Old 06-26-2009, 08:42 AM   #6
AlanM
Talking BlackBerry Encyclopedia
 
AlanM's Avatar
 
Join Date: May 2005
Location: Huntsville, AL
Model: 9930
Carrier: Verizon
Posts: 335
Default

The length of time needed to scrub it dependant on the type of processor in the Blackberry. 88xx will still take somtime, I've seen 87xx take over an hour to wipe the device. I don't think users will see a great deal of slowness with daily use and content protection enabled. One thing that they will notice is that when the device is locked and you have enabled content protection on the addressbook, when you receive a call it will not display the caller's info only the number (addressbook is encrypted remember). If the device is unlocked and you receive a call then the caller info will display (if you have the info in your addressbook). Also, with content protection, if the blackberry OS is pre-4.5 you will not be able to send a password over the air. This is big for us because we do have users that forget their passwords (don't know how) and we have to reset them.

We are most likely due to enforce the Content Protection and media card encryption (password and device) soon.
__________________
AlanM
Exchange\Blackberry Admin
4 - BES Servers (5.0.3),
~1500 BB Users, and a headache.
War Eagle!!
Offline  
Old 06-26-2009, 09:12 AM   #7
misterbulldog
Thumbs Must Hurt
 
misterbulldog's Avatar
 
Join Date: Feb 2006
Location: D.C Metro Area
Model: 9630
OS: 5.0.0.975
Carrier: Verizon
Posts: 164
Default

Quote:
Originally Posted by AlanM View Post
The length of time needed to scrub it dependant on the type of processor in the Blackberry. 88xx will still take somtime, I've seen 87xx take over an hour to wipe the device. I don't think users will see a great deal of slowness with daily use and content protection enabled. One thing that they will notice is that when the device is locked and you have enabled content protection on the addressbook, when you receive a call it will not display the caller's info only the number (addressbook is encrypted remember). If the device is unlocked and you receive a call then the caller info will display (if you have the info in your addressbook). Also, with content protection, if the blackberry OS is pre-4.5 you will not be able to send a password over the air. This is big for us because we do have users that forget their passwords (don't know how) and we have to reset them.

We are most likely due to enforce the Content Protection and media card encryption (password and device) soon.
We completed a Content Protection push to our large BES environment yesterday. We started the project earlier this year. The Address Book was excluded in the policy. Scrubbing will take a while no matter what model you have. We also changed the password policy to require a more complex password so we had quite a few users who forgot their new password as soon as they created it. However, we have found that password resets work with some devices that have 4.2 software and CP. I have not nailed it down to which model/carrier it works with yet. When a user calls for a password reset we give it a try and warn the user that it might not work. If it works, great. If not, oh well.
__________________
BlackBerry® Certified Systems Administrator
Offline  
Old 07-01-2009, 08:06 AM   #8
DarthBBerry
Wireless Sith Lord
 
DarthBBerry's Avatar
 
Join Date: Jan 2007
Location: Online
Model: iOS 6
Carrier: Verizon x2
Posts: 1,458
Default

Quote:
Originally Posted by misterbulldog View Post
We completed a Content Protection push to our large BES environment yesterday. We started the project earlier this year. The Address Book was excluded in the policy. Scrubbing will take a while no matter what model you have. We also changed the password policy to require a more complex password so we had quite a few users who forgot their new password as soon as they created it. However, we have found that password resets work with some devices that have 4.2 software and CP. I have not nailed it down to which model/carrier it works with yet. When a user calls for a password reset we give it a try and warn the user that it might not work. If it works, great. If not, oh well.
The device OS must be 4.2.1 or higher for a password reset with Content Protection to work. If the device is 4.2.0 or less, it won't work. This is from personal, first-hand experience.

We have CP enabled on the devices which includes media cards, password protection, security time out, minimum length, and prohibited passwords. We've been using this model for almost a year with mixed results.
__________________
DarthBBerry
6-Time BlackBerry World Champion (2007-2012)
BlackBerry® Certified Support Specialist v5.0
BlackBerry® Certified System Administrator v5.0
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Sonosite P21x P07698-70 5-1 MHz Transducer w/ P02478-03 ECG Cable picture

Sonosite P21x P07698-70 5-1 MHz Transducer w/ P02478-03 ECG Cable

$1750.00



1/8NPT Stainless Pressure Transducer Sender Sensor For Oil Air Fuel Gas 150Psi picture

1/8NPT Stainless Pressure Transducer Sender Sensor For Oil Air Fuel Gas 150Psi

$13.98



Lowrance PD - WBL Transducer 106 - 73 picture

Lowrance PD - WBL Transducer 106 - 73

$64.95



FREQUENCY TRANSDUCER picture

FREQUENCY TRANSDUCER

$44.99



(Wi-Fi) Pressure Transducer Sender Stainless Steel 1/8NPT Oil Fuel Air Water picture

(Wi-Fi) Pressure Transducer Sender Stainless Steel 1/8NPT Oil Fuel Air Water

$39.00



transducer pressure Universal test meter kit, transducer  Not Included picture

transducer pressure Universal test meter kit, transducer Not Included

$99.00







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.