Weakness is dar's blowfish implementation
Denis Corbin <[email protected]> Mon, 04 Jun 2007 21:29:41 +0200
| Newsgroups | gmane.comp.sysutils.backup.dar.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello, dar's blowfish encryption is weakened by frequent IV collisions. Fix under work (patch proposed), release 2.3.4 will be available when this bug will be fixed. I guess that it is still not easy to access encrypted data without the encryption key, but dar's implementation is not as strong as it could be. Kind Regards, Denis. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGZGgkpC5CI8gYGlIRAgEeAJ0cRpXopiPEflvO+xT3t1WRqT5hNQCgk7SH 7TFNZaAuXsOXRbpmwLKN7nU= =FmZZ -----END PGP SIGNATURE----- ------------------------------------------------------------------------- This SF.net email is sponsored by DB2 Express Download DB2 Express C - the FREE version of DB2 express and take control of your XML. No limits. Just data. Click to get it now. http://sourceforge.net/powerbar/db2/