RE: Cached Domain Password on Notebook, secure?

From: Varga Daniel (QI/RZS4) * (Daniel.Varga@de.bosch.com)
Date: 02/20/02


From: "Varga Daniel (QI/RZS4) *" <Daniel.Varga@de.bosch.com>
To: "'Laura A. Robinson'" <larobins@bellatlantic.net>, focus-ms@securityfocus.com
Date: Wed, 20 Feb 2002 09:03:07 +0100


> No, the security of EFS stands or fails with the location of
> the user and recovery agent keys. Get them off the hard drive.

The user can export his public and private keys onto floppy. But this is for
backup reasons only. He cannot store his keys on external media exclusively
(SmartCard, etc.). So the keys remain on the hard drive, no chance.

An MS-Engineer assured me that it would be incredibly hard for an attacker
to get these keys but he failed to explain me why or how these keys on the
hard drive are protected. Can anyone of you?

thanks

--
Daniel



Relevant Pages

  • Re: When will MS fix the WinCE USB Mass Storage Problems?
    ... All other keys accept this, ... I think the spec does not say that this is a valid response to this command, ... Strangely enough, when my USB analyzer is aquiring, these ... Attachdevice fails, the sequence of state-transitions there, fails. ...
    (microsoft.public.windowsce.platbuilder)
  • Re: When will MS fix the WinCE USB Mass Storage Problems?
    ... In the mean time I got about 50% of my non-working USB keys working. ... Differrent Keys from the same brand behave differently. ... Attachdevice fails, the sequence of state-transitions there, fails. ...
    (microsoft.public.windowsce.platbuilder)
  • Re: When will MS fix the WinCE USB Mass Storage Problems?
    ... some keys that report this status are mounted OK. ... 127852 PID:ebb7ca0a TID:ab776c32 Retry BOT_MassStorageReset ... In the mean time I got about 50% of my non-working USB keys working. ... Attachdevice fails, the sequence of state-transitions there, fails. ...
    (microsoft.public.windowsce.platbuilder)
  • Re: When will MS fix the WinCE USB Mass Storage Problems?
    ... All other keys accept this, ... I think the spec does not say that this is a valid response to this command, ... In the mean time I got about 50% of my non-working USB keys working. ... Attachdevice fails, the sequence of state-transitions there, fails. ...
    (microsoft.public.windowsce.platbuilder)
  • Re: ssh client rejecting key
    ... > new keys and algorithms ... > ninitialize: Destroying authentication method array. ... > looks like it reads a packet of lengh 0 and fails. ...
    (comp.security.ssh)