Orcmid's Lair

Welcome to Orcmid's Lair, the playground for family connections, pastimes, and scholarly vocation -- the collected professional and recreational work of Dennis E. Hamilton

This page is powered by Blogger. Isn't yours?

2004-05-16

 

The nitty-gritty of how not to use encryption

Attacking and repairing the WinZip "Advanced Encryption" scheme.  Here's the skinny on the way software can end up using encryption in an insecure way.  Here's detailed information that is representative of the kinds of diligence it takes to incorporate an encryption system into a product or to use one that has been provided.  There are caveats around the application of almost every cryptographic technique, and one should be careful to know what they are and to safeguard against misuse of the technique.  Finally, it is important to keep asking about the threat one is attempting to mitigate and questioning how a particular security practice actually applies to that.
Comments: Post a Comment
Hard Hat Area

an nfoCentrale.net site

created 2002-10-28-07:25 -0800 (pst) by orcmid
$$Author: Orcmid $
$$Date: 04-05-11 16:50 $
$$Revision: 3 $

Home