RE: PasswordSafe format v3 - discussion
| Newsgroups | gmane.comp.security.passwordsafe.devel |
|---|---|
| Message-ID | <[email protected]> |
I say that this is complete economy. A "magic-number" tag is such an
important part of a file layout that I always assumed that PWS already had
one (I've got to pay closer attention to the file layouts) (Note that every
Zip file starts "PK", every Exe start "MZ")
99.9% of PasswordSafe files can already be identified trivially: By the
existence of Passwordsafe.exe on the machine, then look at
HKEY_CURRENT_USER\Software\Counterpane System\currentfile.
On related notes: The version should be specified in the file itself, but
kept out of the file extension. The file extension should be associated
with the application (double-click the data file to launch the
applications), but the application should not require any particular
extension.
Truth,
James Curran
-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of DK
Sent: Sunday, December 04, 2005 12:09 PM
To: 'Frank Pilhofer'; 'Rony Shapiro';
[email protected]
Subject: RE: [Passwordsafe-devel] PasswordSafe format v3 - discussion
>>> However, I am certainly against this. I would not like anything
recognisable in the file to indicate it is PWS.
>>> I know it is not fool-proof, but why advertise a file as being a PWS
database and inviting it to be cracked (yes, I know, assuming they have
access to the PC etc. etc. etc....)?
-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems? Stop! Download the new AJAX search engine that makes
searching your log files as easy as surfing the web. DOWNLOAD SPLUNK!
http://ads.osdn.com/?ad_id=7637&alloc_id=16865&op=click