Re: Password / Encryption Scheme



most of the security you want would come from
security awareness training of your users

along with management buy in

"Dave McAuliffe" <DaveMcA@xxxxxxxxxxxxxx> wrote in message
news:65p2121onbjlctmdvqm2fcbcm8ujsc4iqm@xxxxxxxxxx
What are the weaknesses in the below plan?

I'm addressing password/keyfile encryption file protection for work
and home purposes. I'm considering using an easy password in the
belief that complex ones need to be written down and therefore pose
their own risk for being breached, and easy ones are nowhere to be
found in writing. In addition, I'm considering the encryption key as
being a part of the password.

The keyfile will *not* be kept on the same computer that it was used
to encrypt. It will be put on floppy, thumbdrive, etc. and kept in
pocket or purse not in the computer case. Therefore you would need
the floppy in order to decrypt the PC file, and if the keyfile were
compromised, it would need to hook up to the PC and then the password
would then need to be known. This separation of the encryption key
and the coming together of three elements, password - keyfile -
computer, is what I'm banking on for relative security.

All personnel (road people) would use the same password/encryption key
file. Any files sent to the office would be decrypted on that end. At
employee turnover, 100% re-encryption would be done with a new keyfile
based on a new password.


--
Dave
Central Mass. USA

To email: Replace
mailinator.com with email.com


.



Relevant Pages

  • Re: alt.computer.security
    ... decryption key for the file to become accessible. ... I'm addressing password/keyfile encryption file protection for work ... I'm considering the encryption key as ... The keyfile will *not* be kept on the same computer that it was used ...
    (microsoft.public.security)
  • Re: if I encrypt key data why do I want or need SSL?
    ... that it's hard to get security right - even for an security ... he can simply decompile it. ... If you are using asymetric encryption, ... The encryption key itself - are you using one for all the encryption ...
    (microsoft.public.dotnet.security)
  • Re: How can I decrypt a Microsoft Word document for which I have the key?
    ... When I talk of having the encryption key, ... security is not an acceptable subject for disussion. ... There may be dedicated security forums somewhere on the net where you could ...
    (microsoft.public.word.docmanagement)
  • Re: Need a Full Drive Encryption program
    ... laptops usually have a security option in the BIOS config. ... Implement a Digital Security policy using win2k. ... Use the max encryption available.. ... backup the encryption key at your ...
    (Security-Basics)
  • Password / Encryption Scheme
    ... I'm addressing password/keyfile encryption file protection for work ... I'm considering using an easy password in the ... I'm considering the encryption key as ... The keyfile will *not* be kept on the same computer that it was used ...
    (alt.computer.security)