Hello Dimitry,

On Tuesday, January 4, 2005 at 9:09:38 PM Dimitry [DA] wrote:

>> Thanks for your answers. I already thought of this solution, but it is
>> a bit complicated for something that should be a basic feature.

DA> Indeed it is.  When you change a password in a situation like this,
DA> the question is also: is the entire message base re-encrypted with (a
DA> hash of) this new password?

This wouldn't be a problem if the password were only there to encrypt
a (randomly generated when OTFE was activated) key used to encrypt the
message base. Of course this key should be rather long than short to
avoid simple brute force attacks, but this way only this key has to
be re-encrypted.
-- 
Regards
Peter Palmreuther

(The Bat! v3.0.2.10 on Windows XP 5.1 Build 2600 Service Pack 2)

The wind blows for free.  How much do you charge?


________________________________________________________
 Current beta is 3.0.2.10 | 'Using TBBETA' information:
http://www.silverstones.com/thebat/TBUDLInfo.html
IMPORTANT: To register as a Beta tester, use this link first -
http://www.ritlabs.com/en/partners/testers/

Reply via email to