Re: Strength in Complexity?

2008-07-08 Thread Ben Laurie
Arshad Noor wrote: Ben Laurie wrote: Arshad Noor wrote: I may be a little naive, but can a protocol itself enforce proper key-management? I can certainly see it facilitating the required discipline, but I can't see how a protocol alone can enforce it. I find the question difficult to

Re: disks with hardware FDE

2008-07-08 Thread Perry E. Metzger
Dries Schellekens [EMAIL PROTECTED] writes: Perry E. Metzger wrote: Has anyone had any real-world experience with these yet? Are there standards for how they get the keys from the BIOS or OS? (I'm interested in how they deal with zeroization on sleep and such.) Most manufacturer (will)

Re: Permanent Privacy - Snake Oil or unbreakable encryption?

2008-07-08 Thread Ali, Saqib
This reads like snake oil. http://www.foxbusiness.com/story/hackers-hell-privacy-compromised/ This reads like a pump'n'dump stock scam. zdnet tries to expose the snake-oil crypto and the pump'n'dump stock scam: http://blogs.zdnet.com/security/?p=1448 good start. but i think they could have

REVIEW: The dotCrime Manifesto, Phillip Hallam-Baker (was Re: [RISKS] Risks Digest 25.22))

2008-07-08 Thread R.A. Hettinga
On Jul 8, 2008, at 2:21 PM, RISKS List Owner wrote: Date: Thu, 03 Jul 2008 11:06:12 -0800 From: Rob Slade [EMAIL PROTECTED] Subject: REVIEW: The dotCrime Manifesto, Phillip Hallam-Baker BKDCRMNF.RVW 20080317 The dotCrime Manifesto, Phillip Hallam-Baker, 2008, 0-321-50358-9, U$29.99/C$32.99