Re: Validation flaw addressed in version 2.14
Greg Thomas <[email protected]>
| Newsgroups | gmane.comp.security.passwordsafe.devel |
|---|---|
| Message-ID | <[email protected]> |
On 11/24/05, James Curran/MVP <[email protected]> wrote: > I've been advocating exactly that for a while, for exactly that > reason. However, a unencrypted timestamp by itself is not good enough -- We > also need some way of knowing which entry is which. I'd recommend adding a > unencrypted GUID to each record. The GUID has the advantage of (a) being > unique and (b) been obscure -- even unencrypted, it provides no information > about the encrypted data. Good point - and a good solution. > For my last suggestion, let's go for something radical.... Why are we > reinventing the database? Why not make the new PasswordSafe file format a > simple MSAccess file. Here the structure would be: At the moment PWS is a relatively small file that requires no installation and can be carried around on a memory stick. Move to something like Access, and you've a multi-megabyte installation file that may well require a reboot on older PCs - suddenly PWS is not quite as convinient as it used to be. Not to mention that Access is hardly cross platform. I can't see any Java or UNIX ports being done for Access ! Greg ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://ads.osdn.com/?ad_idv37&alloc_id865&op=click