Penetration Testing mailing list archives

Re: [PEN-TEST] Password Protection


From: White Vampire <whitevampire () mindless com>
Date: Wed, 11 Oct 2000 19:16:08 -0400

On Wed, Oct 11, 2000 at 11:00:28AM -0700, Jensen, Greg(Greg_Jensen () NAI com) wrote:
Correct, however, we are talking about a means of securing the CD in case it
falls into the wrong hands, not to secure if somebody is using it and
reading it.  If that was the requirement, I would absolutely agree that the
end users need to have PGP installed on thier box so this could be done with
memory protection enabled too.

        That is true.  I suppose I had a completely different line of
thought.  I was thinking of an all-around security solution keeping the
data on the CD.  I suppose that is just a tad anal.  <G>  But then
again, when security is concerned, I try to make as few compromises as
possible.

In this case, the alternative was password protected zip files and pdf's.
Seemed like the obvious solution.

        An ideal solution in my eyes would be something cross-platform
where the data remained on the CD with a high-quality form of
encryption.  This would be used for data that could not have integrity
compromised whatsoever.

-----Original Message-----
From: White Vampire [mailto:whitevampire () mindless com]
Sent: Tuesday, October 10, 2000 11:29 AM
To: PEN-TEST () SECURITYFOCUS COM
Subject: Re: [PEN-TEST] Password Protection

      It was my understanding that SDAs would decrypt the data onto an
available disk.  However, if 'TEMPEST protection' was enabled it would
not.

Regards,
-- 
    __      ______   ____
   /  \    /  \   \ /   / White Vampire\Rem
   \   \/\/   /\   Y   /  http://www.projectgamma.com/
    \        /  \     /   http://www.webfringe.com/
     \__/\  /    \___/    http://www.gammaforce.org/
          \/ "Silly hacker, root is for administrators."

Attachment: _bin
Description:


Current thread: