Harold Fuchs wrote:
On Tuesday, January 23, 2007 4:57 PM [GMT+1=CET],
Dan Lewis <[EMAIL PROTECTED]> wrote:

    Comments inline.

The only real way to defeat a dictionary attack is to destroy the encrypted document after <x> failures (x = 3, 5 ?) and hope the attack isn't lucky within that <x>. One can also delay things considerably by saying "after <x> failed attempts you can't try again for <n> minutes".

I think that this should be the default. Of course if someone wishes, they could write an application to get around this limitation so we are back to a good algorithm to encrypt the data.


--
Robin Laing

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to