Re: Automate GPG or PGP to make an .exe
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


sci.crypt archive

Re: Automate GPG or PGP to make an .exe

From: Sebastian Gottschalk <seppi@seppig.de>
Date: Wed Mar 29 2006 - 05:55:29 CEST

TC wrote:

> Huh? He wants that "the file can be opened by the appropriate user(s)
> ***with a shared password*** on any XP machine".

Which is a very very bad idea, as an attacker could simply modifiy the
binary not to only decrypt the content, but also store the passphrase
somewhere.

Plus that the users get trained on running executables and entering
passphrases without care.

> He just wants to automate the process of typing the password at his
> end, when he creates the file.

Which is another bad idea.
Received on Mon May 1 01:53:03 2006