Re: [VulnDiscuss] EFS vs. Elcomsoft

Chris Wysopal <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>


On Tue, 17 Jun 2003 [email protected] wrote:

> Well, I naively assumed that the user's password was also a factor. If
> that was the case, it would at least require the Elcomsoft program to
> crack a password to get at my sensitive files. From what Microsoft says in
> the link below - it IS the case, but only for a machine that is part of a
> domain or has gone through the floppy fun.

Heh, yes the design could be better but there is a secure way to operate
it.  We all know that unless the secure way is the default way and the
user needs to jump through a hoop to lower their pants the majority of
users will be in pants down mode.

Supposedly Al Qaeda was using EFS on Win2K laptops in Afghanistan.  I
wonder if they used the SYSKEY password.  Any CIA guys want to clue us in?
:)

-Chris
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.