Re: Security - Best Encryption Tool

From: WJ (JohnWebbs_at_HotMail.Com)
Date: 06/03/04

  • Next message: Alek Davis: "Re: Security - Best Encryption Tool"
    Date: Thu, 3 Jun 2004 16:41:39 -0400
    
    

    "Alek Davis" <alek_xDOTx_davis_xATx_intel_xDOTx_com> wrote in message
    news:ObT8D1OSEHA.2408@tk2msftngp13.phx.gbl...

    > Machine Store is not safe. If a hacker manages to get the WRITE access to
    > any of the folders on a compromised machine, he can drop an application
    > there which will decrypt any setting encrypted using DPAPI with machine
    > store.

    This is only possible if one uses Microsoft tool such as the "aspnet_setreg"
    to store your data in the registry database. This tool is one example that
    MS gave, to avoid this "problem", you will almost have to implement your own
    DPAPI (modified) to store your key in other places. However that may be,
    system administrator is responsible to lock his server(s) to avoid misshaps.

    Cheer

    John


  • Next message: Alek Davis: "Re: Security - Best Encryption Tool"

    Relevant Pages

    • Re: Security - Best Encryption Tool
      ... > any of the folders on a compromised machine, ... to store your data in the registry database. ... DPAPI to store your key in other places. ... system administrator is responsible to lock his serverto avoid misshaps. ...
      (microsoft.public.dotnet.framework.component_services)
    • Re: Security - Best Encryption Tool
      ... > any of the folders on a compromised machine, ... to store your data in the registry database. ... DPAPI to store your key in other places. ... system administrator is responsible to lock his serverto avoid misshaps. ...
      (microsoft.public.vb.general.discussion)
    • Re: Security - Best Encryption Tool
      ... > any of the folders on a compromised machine, ... to store your data in the registry database. ... DPAPI to store your key in other places. ... system administrator is responsible to lock his serverto avoid misshaps. ...
      (microsoft.public.dotnet.distributed_apps)
    • Re: Security - Best Encryption Tool
      ... > any of the folders on a compromised machine, ... to store your data in the registry database. ... DPAPI to store your key in other places. ... system administrator is responsible to lock his serverto avoid misshaps. ...
      (microsoft.public.dotnet.framework.aspnet.buildingcontrols)
    • Re: Security - Best Encryption Tool
      ... DPAPI with user store cannot be used from an ASP.NET application unless you ... If you use DPAPI encryption with machine store and your machine ...
      (microsoft.public.dotnet.framework.component_services)