ElcomSoft Co.Ltd. fould a flaw in V3Beta1
"Rony Shapiro" <[email protected]>
| Newsgroups | gmane.comp.security.passwordsafe.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, The good folks at ElcomSoft have found a weakness in the new release that makes the master encryption key vulnerable to a brute-force attack when running pwsafe on pre-XP versions of Windows, basically since we fallback to the rand() prng for those platforms. For more details, see http://www.securityfocus.com/archive/1/428552/30/0/threaded. (It's annoying that they titled their note as a flaw in "3.0", which means I'll probably have to bump the version number to 3.1 when we leave beta...) Aside from hauling in an industrial strength PRNG (Yarrow?) and grovelling around for bits of entropy, does anyone have a suggestion as to how to replace rand or otherwise fix the flaw? Thanks to Markus Jansson for pointing me to the ElcomSoft note. Cheers, Rony ------------------------------------------------------- This SF.Net email is sponsored by xPML, a groundbreaking scripting language that extends applications into web and mobile media. Attend the live webcast and join the prime developer group breaking into this new coding territory! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642