Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 514685
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 13, 20262026-05-13T07:33:02+00:00 2026-05-13T07:33:02+00:00

I am evaluating a requirement for a consumer blackberry application that places high premium

  • 0

I am evaluating a requirement for a consumer blackberry application that places high premium on security of user’s data. Seems like it is an insurance company. Here are my ideas on how I could go about it. I am sure this would be useful for others who are looking for similar stuff

  • Force the user to use device password. (I am guessing that this would be possible – though not checked it yet). Application can request notifications when the device is about to be locked and just after it has been unlocked. Encryption of application specific data can be managed at those times.
  • Application data would be encrypted with user’s password.
  • User’s credentials would be encrypted with device password.
  • Remote backup of the data could be done over HTTPS (any better ideas are appreciated)

Questions:

  1. What if the user forgets his device password.
  2. If the user forgets his application password, what is the best and secure way to reset the password?
  3. If the user losses the phone, remote backup must be done and the application data must be cleaned up.

I have some ideas on how to achieve (3) and shall share them. There must be an off-line verification of the user’s identity and the administrator must provide a channel using which the user must be able to send command to the device to perform the wiping of application data. The idea is that the user is ALWAYS in control of his data. Without the user’s consent, even the admin must not be able to do activities such as cleaning up the data.

In the above scheme of things, it appears as if the user’s password need not be sent over the air to server. Am I correct?

Thanks,

–Kiran Kumar

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-13T07:33:02+00:00Added an answer on May 13, 2026 at 7:33 am

    If by device password you are refering to the one set at Options -> Password, if it is lost the data on the device will no longer be recoverable (especially if data protection is enabled). A BES can force a device password, an application can’t. The best you could do is not operate unless a password has been set, but as far as I know you can’t determine if one has, or has not. The device could be locked with the simple keyboard lock.

    Any scheme where the server has any knowledge of users’ passwords is only as secure as the server. There are ways to authenticate users without exchanging a password.

    I have to say though, as a BES administrator, some of the features you are planning would result in us blacklisting your software. No one wipes our Blackberries but us.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I am working on a web application that has strict security and auditing requirements
I'm currently evaluating the use of ADO.NET for a C++ application that currently uses
When evaluating the value of myObject.myMember My guess is that javascript will try to
Evaluating Tinymce. I've looked at the docs/source/api, and have a question that I thought
I'm evaluating Hibernate Shards for a project that uses hibernate-jpa. I was wondering how
I'm currently evaluating possible solutions to the follwing problem: A set of data entries
Currently evaluating Dreamweaver CS 5.5. I like much of it - but wondering about
While evaluating Visual Studio 2010 Beta 2, I see that in the converted directory,
I am working on evaluating few design patterns and frameworks. Application design should support
I'm evaluating a number of windows installer tools for our application. Some of them

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.