Re: Validation flaw addressed in version 2.14

Greg Thomas <[email protected]>
Newsgroups gmane.comp.security.passwordsafe.devel
Message-ID <[email protected]>
On 11/24/05, James Curran/MVP <[email protected]> wrote:
>         I've been advocating exactly that for a while, for exactly that
> reason.  However, a unencrypted timestamp by itself is not good enough -- We
> also need some way of knowing which entry is which.  I'd recommend adding a
> unencrypted GUID to each record.  The GUID has the advantage of (a) being
> unique and (b) been obscure -- even unencrypted, it provides no information
> about the encrypted data.

Good point - and a good solution.

> For my last suggestion, let's go for something radical.... Why are we
> reinventing the database? Why not make the new PasswordSafe file format a
> simple MSAccess file.  Here the structure would be:

At the moment PWS is a relatively small file that requires no
installation and can be carried around on a memory stick. Move to
something like Access, and you've a multi-megabyte installation file
that may well require a reboot on older PCs - suddenly PWS is not
quite as convinient as it used to be.

Not to mention that Access is hardly cross platform. I can't see any
Java or UNIX ports being done for Access !

Greg


-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems?  Stop!  Download the new AJAX search engine that makes
searching your log files as easy as surfing the  web.  DOWNLOAD SPLUNK!
http://ads.osdn.com/?ad_idv37&alloc_id865&op=click
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.