Re: Cryptography and Site Security: Please critique my security idea

From: Robert Paris (rpjava@hotmail.com)
Date: 03/26/03


From: rpjava@hotmail.com (Robert Paris)
Date: 26 Mar 2003 10:14:43 -0800

Sebastian Hoehn <shoehn@web.de> wrote in message news:<3E816B6F.9060103@web.de>...
> Hi,
> I guess your idea is not very save. The problem is you establish a key
> server. So the secrecy of your documents depends completely on the
> secrecy of this server. Who can guarantee for that?

Wait, what are you talking about? As I stated, there is no access to
the computer housing the keys from the client, the server or outside
the internal network. Of course SOMEONE has to have access to those
keys, but that is only one or two authorized people. They manage all
the keys. You certainly can't give access to the keys to no one. And
they have to explicitly access those keys to do something with them,
so we can monitor that.

> The problem you have cannot really be solved as long as you have some
> "legitimate" users. There will always be a way to get illegitimate
> access. Why don't you set the documents server behind a firewall with
> just port 443 for ssl open. So the "only entrance" to that is the SSL
> Browser. So there is no other vulerability as that of the SSL Protocol.
> Now you can be pretty sure that the only Problems you face is you web
> application.

It will be behind a firewall, but that's NOT a guarantee no one can
break into the box. (Whether through hacking or through someone
letting them get access directly into the box)

> Another security addon you could have is simply encrypt your documents
> and use a servlet for decryption before delivery.

???!!! Did you read what I posted? Please go back and read it again.



Relevant Pages

  • RE: SBS SHared Printer Problem
    ... Does this issue happen for all the client workstations? ... If you try printing on the SBS server, ... Clear the registry keys and the driver on both the server and the client ... Microsoft Shared Fax Monitor ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS SHared Printer Problem
    ... They are shared from the server. ... please right click following registry keys and click ... Microsoft Shared Fax Monitor ... Install the latest driver for the printer and check if the issue ...
    (microsoft.public.windows.server.sbs)
  • Re: uniqid() function
    ... value if the PHP script is on only one server? ... Why do you not use the autoincrement featuer of the Database? ... - In these times you might need to actually create the data structure ... So you generate all the keys outside your server ...
    (comp.lang.php)
  • Re: Stupid license key question - OEM
    ... I haven't dealt with OEM for SBS 2008 Premium, ... Using Windows Small Business Server 2008 Product Keys ... product key, the product key is provided on the Certificate of Authenticity ...
    (microsoft.public.windows.server.sbs)
  • RE: sshd / ssh setup
    ... USA server and his windows/xp notebook to use SSH. ... followed sshd instruction and built ... and require users to submit keys. ...
    (freebsd-questions)