Re: Status of the Java Port?
Cyrus242 <[email protected]>
| Newsgroups | gmane.comp.security.passwordsafe.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, I'm sorry. I guess my choice of words 'failed' in conveying my meaning. I have been using Password Safe and will continue doing so. I definitely want to take a look at the java port that has been done. The only problem I fear is the format its currently in: We will have to look at doing what's known as a 3-Tier application. Should we look at taking the java port in this direction or make a project fork? -Dustin Eric Venegas Rony Shapiro wrote: >Hi, > >I don't think that PasswordSafe has "failed" by any reasonable definition of >the term. It does what it was designed to do quite well, and I am not aware >of any breaches in the security or cryptography (note that the terms are not >synonymous). But then again, I may be a bit biased :-) > >If you're interested in a Java port, the CVS repository has some work that >was done a while ago that might serve as the basis for a downloadable >applet. > > Cheers, > > Rony > >________________________________ > > From: [email protected] >[mailto:[email protected]] On Behalf Of >Cyrus242 > Sent: Monday, May 02, 2005 12:42 AM > To: [email protected] > Subject: Re: [Passwordsafe-devel] Status of the Java Port? > > > > > Greg Thomas wrote: > > On 5/1/05, Cyrus242 <[email protected]> ><mailto:[email protected]> wrote: > > > my group would be interested in talking about why >this password > safe has failed and what can be done to make a >better one. > > > > FWIW, I don't think PS has "failed". Time has moved on, and >it is > perhaps not quite as secure as it could be. That said, I >consider if > safe enough. OK, it may not be good enough for state >secrets, but it > will keep my online banking details out of Joe Hackers >hands. > > Either way, it's nothing that a couple of new encryption >routines > wouldn't solve. > > > > I do not think C++ is a candidate >language as none of us know it. C# and > JAVA seem likely candidates as well as a possibility >for PHP or another > web based language. I am personally pushing for Java >or C#. > > > > PHP etc. are (generally) server side languages. That's no >good, unless > you can trust your server 100%, which most people can't. If >you want a > WWW based solution, I think the only option would be a Java >applet > that uploads/downloads the encrypted file to the server, and >decrypts > it locally. You can digitally sign the applet so you know it >hasn't > been tampered with. > > Greg > > > > PHP or another simple solution would be done only if time >constraints are put in place beyond our control. A java applet did pass by >my mind as a solution. Again though, I would personally prefer to use Java >or C# to have a 'password safe' with proper security measures. > > > > >------------------------------------------------------- >This SF.Net email is sponsored by: NEC IT Guy Games. >Get your fingers limbered up and give it your best shot. 4 great events, 4 >opportunities to win big! Highest score wins.NEC IT Guy Games. Play to >win an NEC 61 plasma display. Visit http://www.necitguy.com/?r=20 >_______________________________________________ >Passwordsafe-devel mailing list >[email protected] >https://lists.sourceforge.net/lists/listinfo/passwordsafe-devel > > > ------------------------------------------------------- This SF.Net email is sponsored by: NEC IT Guy Games. Get your fingers limbered up and give it your best shot. 4 great events, 4 opportunities to win big! Highest score wins.NEC IT Guy Games. Play to win an NEC 61 plasma display. Visit http://www.necitguy.com/?r=20