I lost a USB drive, I think. It had some stuff on there - nothing crazy - but, for instance, a file with some passwords to websites I visit (obviously nothing that's really all that important). I encrypted it with winzip's 256 bit encryption and a very nice password. Is this a true encryption technique that winzip uses - ie. it would require the typical brute force approach that other 256 would require, thus making it for all intents and purposes totally unbreachable?
http://eprint.iacr.org/2004/078.pdf This is an indepth discussion of Winzip's security. It covers some of the weak points, but my interpretation, after reading the first 1/3, is that somebody with my winzip file, though able to read the content's names (I knew that) will be unable to actually access what is within them.
+ Reply to Thread
Results 1 to 10 of 10
-
-
I rememebered that I had forgotten the password for a personal rar-ed file and I tried to crack the passowrd which was 256 bit encrypted. Man, the cracker just denied to help me.
So, I think you dont have to worry unless someone knows you have your bankaccount code stored in there so it makes it worth the f/&%in' effort to crack the password. -
It's got some pics of a family vacation, and otherwise everything on it was encrypted. They can read the file names - the "worst" being my passwords file and then my 2003 tax return, but even if somebody got them I wouldn't care that much, and if they can get around the 256 encryption, hell all the power to them
-
It'll keep most people out.
I wouldn't worry too much but if you do want to lower the chances I'd post a $20 buck reward for its return, thats of course, if you know the general area that it was lost. -
I think the stronger Winzip encryption is fine though it is not compatible with other "ZIP" capable programs.
The older/original ZIP encryption (i.e., universally compatible) is weak. You can download tools on the internet to crack it.
It is suspectable to brute force dictionary type attacks as well as a true cryptographic method as well.
Regards.Michael Tam
w: Morsels of Evidence -
There`s no way to extract Paswords from a winzip archive. The only way to find passwords is to use "brut force" of a good computer (test every number & letter in all possible combinations) with a program I used few years ago .The password configures the way WINZIP scrambles information in compressing method ,so, it`s no way you can find it hidden in the archive because it simply isn`t there. If the password is longer then 6 caracters you`ll have to wait maybe severall hours of computer work...if the password is longer then 9 caracters maybe days...
-
Originally Posted by AlinaVastag84
Hopefully it did
As an aside, what do others here use for this sort of thing? I just need to have files local to me and as secure as possible. I know XP has something built in, but that seems a bit of a hassle to use. I'd want something as easily accessible as possible, while still being for all intents and purposes unbreakable. -
I d/I'd a file that was encrypted. Just for the hell of it I tried a .rar decrypting program. It said 56hrs projected with brute force method. I ran it for three days. No luck. Depending on how many characters the password is and how convoluted., (combo of symbols, numbers, alphabet) and how fast your system is, really an enormous task.
If you have a file you don't want decrypted, go for a complex password. Numbers, symbols, alphabet. More is better. Just make sure you write the PS down, or nobody, including you, will crack it.
The average person that finds a hardware device with files on it will hopefully try to return it, or may try to open it once or twice. If that doesn't work they will either reformat it or throw it in the trash. If they don't know what's on it, they won't go to any effort.
There are plenty of security sites on the web. If you want to really find out about encryption and password security, check them out. -
Read what I read before.
If you try to crack the older Winzip encryption with "brute" force, you are well worth your while to try a dictionary attack first (i.e., rather than cycle through every single combination of characters, it tries a vast database of WORDS first).
Most people use a "word" for their password. If so, it will probably get broken in SECONDS.
If you use a LONG password with letters and numbers (i.e., something that can't be cracked using a dictionary search), it will take a relatively long time to crack on a PC.
As I also stated before though, the older Winzip encryption method was also subject to a different type of cryptographic attack (NOT brute force). Do a Google search on it -- there was a paper written on it and I was pretty sure that there was beta software released as well. You did need a "crib" though (i.e., some known ciphertext) for the attack to work. It is this second attack which makes the Winzip encryption system ultimately weak as it isn't dependent on your "key strength".
Regards.Michael Tam
w: Morsels of Evidence -
Originally Posted by Skoorb
Storing a few dummy password protected zip files in the same directory with your valuable info will deter anyone from trying. If you put 9 more files then they have a one in ten chance of hitting the right file even if they managed to crack one.
Similar Threads
-
LAME 32-bit or 64-bit in EAC under Windows 7 64-bit?
By flashandpan007 in forum AudioReplies: 1Last Post: 12th Apr 2011, 09:40 -
x264 will not be using the new 256 bit avx instruction set
By deadrats in forum Video ConversionReplies: 6Last Post: 8th Nov 2010, 18:30 -
winzip hijacking my iso file!
By sportflyer in forum Newbie / General discussionsReplies: 3Last Post: 15th Jan 2010, 00:09 -
Firewire Connection - how to secure??
By motown01 in forum Camcorders (DV/HDV/AVCHD/HD)Replies: 1Last Post: 23rd Nov 2009, 13:39 -
OT: video file locked in password protected winzip?
By BIFFtheSTIFF in forum Newbie / General discussionsReplies: 0Last Post: 24th Oct 2009, 14:01