Re: Decrypting .dat files

Philip Newton <[email protected]> Thu, 11 Nov 2004 14:33:27 +0100
Newsgroups gmane.comp.security.passwordsafe.user
Message-ID <[email protected]>
On Thu, 11 Nov 2004 10:12:38 +0100, Schreck, Juergen
<[email protected]> wrote:
> I think this would be against all
> purposes of pwsafe. If it would be so easy to decrypt the database you could
> hold your passwords in a plain textfile, too.

I though the main component of security lies in the choice of key, not
in the specific algorithm.

After all, decrypting the database by starting pwsafe is also "easy"
if you have the right passphrase; I do not see why a command-line
decryption utility *that requires you to know the passphrase* is less
secure.

Cheers,
-- 
Philip Newton <[email protected]>


-------------------------------------------------------
This SF.Net email is sponsored by:
Sybase ASE Linux Express Edition - download now for FREE
LinuxWorld Reader's Choice Award Winner for best database on Linux.
http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click