Search:  

 
theme to black backgroundlet page decide theme
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Steganos Safe 2007 / 2008 built-in password generator.
Uniqs:
157
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
N/M »
« Most home routers 'vulnerable to remote take-over'  

waldovanlaeken

@belgacom.be

Steganos Safe 2007 / 2008 built-in password generator.

Hey !

I'm a user of Steganos Safe 2007 (not the Pro version with keyrecovery option). I don't trust this.

I do have questions about the built-in password generator they use.

If you make a new safe, you have the option to provide a password (i use 70 random characters) that is 280 binary-bits.

I know this is 6 charaters to much (for the 256-Bits AES) for maximum strength. But this is just a little safety margin.

You also get the option to safe a "keyfile" to a removable media for easy entry to the vault.

This keyfile is generated by steganos. So you get the option to open your safe with the password you provided, OR with the keyfile for easy entry.

my problem (question) is why is the password in the generated keyfile only 64-characters long (if you convert to .txt you can see it) if you have the option for manually type password up to 100 characters ??

So the weakness is Not always the password you type yourself, but could reside in the key-generator in steganos !

Wich algorithm do they use to derivate the keyfile ? (hash function).

do they ad random bits (salt) or truly random bits derivated on mouse movements ?? or something else...

There is NO information on this ?

Does somebody knows more about this program that is worldwide used ?

(Steganos support didn't answer me)

Thanks !
Forums » Up and Running » Security » SecurityN/M »
« Most home routers 'vulnerable to remote take-over'  


Thursday, 26-Nov 21:21:13 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [109] New AT&T Ad Campaign Hits Back At Verizon
· [107] Time Warner Cable Fires Broadside At Broadcasters
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [69] TiVo Sees Record Customer Losses
· [61] In-Flight Internet Headed For Bumpy Landing?
· [48] Thanksgiving Open Thread
· [37] ICANN Slams DNS Redirection
· [35] EFF Wages War On Fine Print
· [34] Senators Want ACTA Made Public
Most people now reading
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· I'll Just Unplug That... [No, I Will Not Fix Your #@$!! Computer]
· Bell Response to PIPEDA Request [TekSavvy]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Newegg Black Friday Sale started [Users Find Hot Deals]
· Windows 7 boot manager editing questions [Microsoft Help]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]