OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [ISN] Is Win2000 secure?

From: mea culpa (jerichoDIMENSIONAL.COM)
Date: Thu Nov 04 1999 - 13:01:59 CST


Response From: Felix von Leitner <leitnervim.org>

Thus spake mea culpa (jerichoDIMENSIONAL.COM):
> From: darek.milewskius.pwcglobal.com
> From: NWFusion Focus [mailto:newsgaeta.itwpub1.com]

> NETWORK WORLD FUSION FOCUS: JIM REAVIS on SECURITY

[...]

> * Encrypted File System. One component is transparent file encryption on
> NTFS file systems, configurable on a per folder/file basis. The underlying
> encryption algorithm is standard DES, using 128 bit keys for North America
> and 40 bit keys internationally. [...]

This author obviously has absolutely no idea what he is talking about
and his articles should be blacklisted from ISN for the next millenium.
There is no 128-bit standard DES.

[key recovery]
> An analysis of EFS key recovery by security
> analysts is ongoing;

Not really.
It was immediately clear that the default storage position is insecure.
This is another prime example of Microsoft marketing. What has b/s like
this to do on a reputable mailing list like this? Nothing, if you ask
me.

Felix

ISN is sponsored by Security-Focus.COM