ElcomSoft Co.Ltd. fould a flaw in V3Beta1

"Rony Shapiro" <[email protected]>
Newsgroups gmane.comp.security.passwordsafe.devel
Message-ID <[email protected]>
Hi,

The good folks at ElcomSoft have found a weakness in the new release that
makes the master encryption key vulnerable to a brute-force attack when
running pwsafe on pre-XP versions of Windows, basically since we fallback to
the rand() prng for those platforms. For more details, see
http://www.securityfocus.com/archive/1/428552/30/0/threaded. (It's annoying
that they titled their note as a flaw in "3.0", which means I'll probably
have to bump the version number to 3.1 when we leave beta...)

Aside from hauling in an industrial strength PRNG (Yarrow?) and grovelling
around for bits of entropy, does anyone have a suggestion as to how to
replace rand or otherwise fix the flaw?

Thanks to Markus Jansson for pointing me to the ElcomSoft note.

	Cheers,

		Rony





-------------------------------------------------------
This SF.Net email is sponsored by xPML, a groundbreaking scripting language
that extends applications into web and mobile media. Attend the live webcast
and join the prime developer group breaking into this new coding territory!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.