Path: csiph.com!usenet.pasdenom.info!gegeweb.org!eternal-september.org!feeder.eternal-september.org!mx04.eternal-september.org!.POSTED!not-for-mail From: Jim Janney Newsgroups: comp.sys.mac.apps Subject: Re: Encryption Date: Wed, 08 Aug 2012 16:14:44 -0600 Organization: not at this time Lines: 48 Message-ID: References: <5020e138$0$1736$c3e8da3$3a1a2348@news.astraweb.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Injection-Info: mx04.eternal-september.org; posting-host="3e796541df3cd2e39d75fcba86cc47b9"; logging-data="708"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+cC93rqGqC9SN8vltmA7td" User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/23.1 (gnu/linux) Cancel-Lock: sha1:BMLC4su3kmevgfUcTBqPb9gTLnU= sha1:jFUuSWkXp+8BZqN2g+/r6qMr7Ik= Xref: csiph.com comp.sys.mac.apps:11476 Paul Sture writes: > On Tue, 07 Aug 2012 22:36:54 -0400, Wes Groleau wrote: > >> On 08-07-2012 20:07, Jim Janney wrote: >>> Gary writes: >>>> I have a text document which I use to keep track of my passwords, >>>> logins, program registration codes, etc. >>>> >>>> I am concerned about the havoc that could result from it getting into >>>> the wrong hands, especially with the potential exposure of iCloud and >>>> Dropbox services. >>>> >>>> Does anyone know of a simple technique I can use to encrypt it such >>>> that I could decrypt it (by knowing the password to the file) either >>>> on iPhone, iPad, Mac desktop or PC laptop? >>> >>> Wuala covers all those platforms and is at least theoretically safe >>> from cracking, since the server only sees your data after it's been >>> encrypted. >>> >>> http://www.wuala.com/ >> >> You know, I think the are probably safe. But I feel obligated to point >> out that it is _possible_ the app also passes the decryption key over to >> them. > > The other point about Wuala is that it requires Java. Given the number > of security holes that have been found in Java, I don't really want to > run it on every system. Once Apple cease software updates for the > versions of OS X which contain Apple's Java distribution, that could get > worse. > > This is already the case for Leopard, Given the informed guesses in this > newsgroup about likely dates that Apple stop issuing updates for Snow > Leopard, it is something to be considered. > > A reminder about Flashback: > > leopard-in-sync-with-oracle/> As it happens, I'm running Snow Leopard with Java installed, but I have Java turned off in Safari. Other than running malicious applets, are there any security holes I should worry about? -- Jim Janney