Re: [VulnDiscuss] EFS vs. Elcomsoft

Chris Wysopal <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
Isn't this a well known issue?  EFS is only secure if the computer is part
of a domain or the user uses one of the stronger syskey modes: password
prompt or key on floppy.  A cryptosystem that has all the keys sitting
there for an adversary to deobfuscate can never be secure.

Elcomsoft info:
http://www.elcomsoft.com/AEFSDR/readme.txt

Microsoft info:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/news/efs.asp

-Chris

On Tue, 17 Jun 2003 [email protected] wrote:

> So I think it's interesting that no one has made special note that
> Elcomsoft totally smashed through Microsoft's encrypted file system, and
> now sells an application that allows people to easily unencrypt files from
> disk images. I know a lot of CxO's that think encrypting their company's
> documents with EFS is making them more secure, but it turns out apparantly
> the key is stored in the registry. Elcomsoft did a talk on it for BlackHat
> Europe, but nothing has been posted to anywhere that stressed that for 99
> bucks, every CxO's documents  on a imaged disk are all cleartext.
>
> Dave Aitel
> Immunity, Inc.
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.