RE: Validation flaw addressed in version 2.14
"Rony Shapiro" <[email protected]>
| Newsgroups | gmane.comp.security.passwordsafe.devel |
|---|---|
| Message-ID | <[email protected]> |
David, The preferences are written both to the registry and to the database. At the time, this was done for backwards compatability. corelib/PWSPrefs.cpp is where you want to look. As to the cipher, having less resources thrown at attacking Twofish can be considered an advantage compared to AES... Also, Twofish was an AES finalist, so it's not that it's not been analyzed at all. Cheers, Rony > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On > Behalf Of [email protected] > Sent: Saturday, November 26, 2005 9:59 PM > To: Rony Shapiro > Cc: [email protected] > Subject: RE: [Passwordsafe-devel] Validation flaw addressed > in version 2.14 > > Rony, > > Re: Preferences - I am surprised, as whenever I have added a function/property > to PWS using the standard PWSpref (GetPref & SetPref functions), they have > always gone into the Registry! I must look at the code again. Maybe my > additions have always been more "global" than "database specific" but I do not > remember having the option to add (or not) the values to the database nor to > signify global vs. local? > > Re: Ciphers - Mainly "marketing". However, the reason > Twofish "has no known > attacks as of now" could be because it isn't used much, so > why bother trying to > attack it? ;-) > > Regards, > > David > ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://ads.osdn.com/?ad_id=7637&alloc_id=16865&op=click