Re: encrypting received faxes before emailing

A J Stiles <[email protected]>
Newsgroups gmane.comp.telephony.fax.hylafax.user
Message-ID <[email protected]>
On Monday 25 Jan 2016, John Hudak wrote:
> Thank you for the suggestion.  I am curious though, could you please tell
> me why 256-bit AES encoded file which is the cypher I plan on using,  is
> "about as secure as putting a padlock through the zip sliders of a tent"?

I used to get sent passworded ZIP files by e-mail, followed by the password in 
an SMS message a bit later .....  usually after I had already cracked the 
original ZIP file.  O.K., it required a modest arsenal of hacking tools, but I 
personally would not trust it.  (At least they didn't put the password in the 
same e-mail with the file attached .....  which was essentially the same 
mistake the DVD-CCA made.)
 
> From my readings (mostly papers on cyphers, some time ago), 256 AES was
> 'one of the top ones'....

But it's still only as secure as the password  (a dictionary word gives about 
16 bits of entropy),  and you need a separate channel for distributing the 
passwords.

> having just read info about gnupg, I see it is a hybrid encryption
> program...not clear what that buys me....

It implements OpenPGP public-key encryption.  This is based on an asymmetric 
cipher.  Only the decrypting key is secret, nobody save the intended recipient 
ever even needs to know it,  and crucially it can't be deduced from the public  
(encrypting)  key -- if you try, you just end up with more simultaneous 
equations than variables.


-- 
AJS
(Originating address does not accept e-mail.  Insert a figure "one" before the 
at sign if replying off-list.)


____________________ HylaFAX(tm) Users Mailing List _______________________
  To subscribe/unsubscribe, click http://lists.hylafax.org/cgi-bin/lsg2.cgi
 On UNIX: mail -s unsubscribe [email protected] < /dev/null
  *To learn about commercial HylaFAX(tm) support, mail [email protected].*
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.