Re: Status of the Java Port?

Greg Thomas <[email protected]>
Newsgroups gmane.comp.security.passwordsafe.devel
Message-ID <[email protected]>
On 5/1/05, Cyrus242 <[email protected]> wrote:
> my group would be interested in talking about why this password
> safe has failed and what can be done to make a better one.

FWIW, I don't think PS has "failed". Time has moved on, and it is
perhaps not quite as secure as it could be. That said, I consider if
safe enough. OK, it may not be good enough for state secrets, but it
will keep my online banking details out of Joe Hackers hands.

Either way, it's nothing that a couple of new encryption routines
wouldn't solve.

> I do not think C++ is a candidate language as none of us know it. C# and
> JAVA seem likely candidates as well as a possibility for PHP or another
> web based language. I am personally pushing for Java or C#.

PHP etc. are (generally) server side languages. That's no good, unless
you can trust your server 100%, which most people can't. If you want a
WWW based solution, I think the only option would be a Java applet
that uploads/downloads the encrypted file to the server, and decrypts
it locally. You can digitally sign the applet so you know it hasn't
been tampered with.

Greg


-------------------------------------------------------
This SF.Net email is sponsored by: NEC IT Guy Games.
Get your fingers limbered up and give it your best shot. 4 great events, 4
opportunities to win big! Highest score wins.NEC IT Guy Games. Play to
win an NEC 61 plasma display. Visit http://www.necitguy.com/?r
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.