Re: [VulnDiscuss] EFS vs. Elcomsoft
Chris Wysopal <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 17 Jun 2003 [email protected] wrote: > Well, I naively assumed that the user's password was also a factor. If > that was the case, it would at least require the Elcomsoft program to > crack a password to get at my sensitive files. From what Microsoft says in > the link below - it IS the case, but only for a machine that is part of a > domain or has gone through the floppy fun. Heh, yes the design could be better but there is a secure way to operate it. We all know that unless the secure way is the default way and the user needs to jump through a hoop to lower their pants the majority of users will be in pants down mode. Supposedly Al Qaeda was using EFS on Win2K laptops in Afghanistan. I wonder if they used the SYSKEY password. Any CIA guys want to clue us in? :) -Chris