<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Steganos Safe 2007 / 2008 built-in password generator. in Security</title>
<link>http://www.dslreports.com/forum/r19811434</link>
<description></description>
<language>en</language>
<pubDate>Wed, 10 Feb 2010 07:38:43 EDT</pubDate>
<lastBuildDate>Wed, 10 Feb 2010 07:38:43 EDT</lastBuildDate>

<item>
<title>Steganos Safe 2007 / 2008 built-in password generator.</title>
<link>http://www.dslreports.com/forum/remark,19811434</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hey !<br><br>I'm a user of Steganos Safe 2007 (not the Pro version with keyrecovery option). I don't trust this.<br><br>I do have questions about the built-in password generator they use.<br><br>If you make a new safe, you have the option to provide a password (i use 70 random characters) that is 280 binary-bits.<br><br>I know this is 6 charaters to much (for the 256-Bits AES) for maximum strength. But this is just a little safety margin.<br><br>You also get the option to safe a "keyfile" to a removable media for easy entry to the vault.<br><br>This keyfile is generated by steganos. So you get the option to open your safe with the password you provided, OR with the keyfile for easy entry.<br><br>my problem (question) is why is the password in the generated keyfile only 64-characters long (if you convert to .txt you can see it) if you have the option for manually type password up to 100 characters ??<br><br>So the weakness is Not always the password you type yourself, but could reside in the key-generator in steganos !<br><br>Wich algorithm do they use to derivate the keyfile ? (hash function).<br><br>do they ad random bits (salt) or truly random bits derivated on mouse movements ?? or something else...<br><br>There is NO information on this ?<br><br>Does somebody knows more about this program that is worldwide used ?<br><br>(Steganos support didn't answer me)<br><br>Thanks !]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19811434</guid>
<pubDate>Wed, 16 Jan 2008 07:48:42 EDT</pubDate>
</item>

</channel>
</rss>
