Re: Encrypted configuration file?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


sci.crypt archive

Re: Encrypted configuration file?

From: Kristian Gjøsteen <kristiag+news@math.ntnu.no>
Date: Sun Apr 30 2006 - 15:21:53 CEST

Mike Amling <nospam@foobaz.com> wrote:
> When you say the MAC trick will work, I wonder how the attacker is
>detected if she surreptitiously installs a previously valid
>configuration file?

He isn't detected. You are of course correct, this is a problem. You
need some kind of tamper-proof state to detect it.

One way to mitigate this problem is to include a date in the configuration
file and display it prominently when the password is entered.

-- 
Kristian Gjøsteen
Received on Mon May 1 02:06:22 2006