|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: PGP 6.5.1 has been released
Kenneth Albanowski (kjahds
KJAHDS.COM)
Mon, 12 Jul 1999 19:20:13 -0400
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
- Next message: Thomas 'Balu' Walter: "Re: IGMP fragmentation bug in Windows 98/2000"
- Previous message: John Hall: "Re: Exploit of rpc.cmsd"
- In reply to: Bob Todd: "Exploit of rpc.cmsd"
- Next in thread: Nick_: "Re: PGP 6.5.1 has been released"
On Wed, 7 Jul 1999, Steven M. Bellovin wrote:
> >Self-Decrypting Archives. You may now encrypt files or folders into
> >Self-Decrypting Archives (SDA) which can be used by users who do not even
> >have PGP. The archives are completely independent of any application,
> >compressed and protected by PGP's strong cryptography.
>
> I'm glad this was on bugtraq -- any crypto product with "self-decrypting
> archives" is a serious security threat, at least for the other versions I've
> seen. They involve an executable that does *something* -- but what? The
> world has recently learned what I hope the folks on this list have long
> known -- that you can't trust email with executable content.
For what it is worth, I'd consider an SDA to have one specific benefit in
a data storage situation: if recovery of the data is needed in an
emergency, or at a time in the future when locating the encryption
software is difficult, the chances are much better that you'll be able to
get the data unpacked. (You can accomplish something similar by storing a
copy of the PGP executable near the data.)
However, for data communications, I'd agree that SDAs are just tempting
fate. They might be used successfully in some particular situations
(transmission over of data & executable over channels that can be snooped
but not modified) but seem to be tempting fate.
-- Kenneth Albanowski (kjahdskjahds.com, CIS: 70705,126)
- Next message: Thomas 'Balu' Walter: "Re: IGMP fragmentation bug in Windows 98/2000"
- Previous message: John Hall: "Re: Exploit of rpc.cmsd"
- In reply to: Bob Todd: "Exploit of rpc.cmsd"
- Next in thread: Nick_: "Re: PGP 6.5.1 has been released"
This archive was generated by hypermail 2.0b3 on Mon Jul 12 1999 - 22:19:53 CDT