Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.apps > #11438 > unrolled thread

Encryption

Started byGary <gary_w1@hotline.com>
First post2012-08-07 05:34 -0400
Last post2012-08-07 23:12 -0400
Articles 10 — 8 participants

Back to article view | Back to comp.sys.mac.apps


Contents

  Encryption Gary <gary_w1@hotline.com> - 2012-08-07 05:34 -0400
    Re: Encryption nospam <nospam@nospam.invalid> - 2012-08-07 09:45 -0400
      Re: Encryption Harald Hanche-Olsen <hanche@math.ntnu.no> - 2012-08-07 18:23 +0200
        Re: Encryption nospam <nospam@nospam.invalid> - 2012-08-07 12:43 -0400
    Re: Encryption "Douglas C. Neidermeyer" <sgt@arms.omega.faber.edu> - 2012-08-07 10:34 -0400
    Re: Encryption Jim Janney <jjanney@shell.xmission.com> - 2012-08-07 18:07 -0600
      Re: Encryption Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 22:36 -0400
        Re: Encryption Paul Sture <paul@sture.ch> - 2012-08-08 11:01 +0200
          Re: Encryption Jim Janney <jjanney@shell.xmission.com> - 2012-08-08 16:14 -0600
    Re: Encryption Bob Harris <nospam.News.Bob@remove.Smith-Harris.us> - 2012-08-07 23:12 -0400

#11438 — Encryption

FromGary <gary_w1@hotline.com>
Date2012-08-07 05:34 -0400
SubjectEncryption
Message-ID<5020e138$0$1736$c3e8da3$3a1a2348@news.astraweb.com>
I have a text document which I use to keep track of my passwords, 
logins, program registration codes, etc.

I am concerned about the havoc that could result from it getting into 
the wrong hands, especially with the potential exposure of iCloud and 
Dropbox services.

Does anyone know of a simple technique I can use to encrypt it such 
that I could decrypt it (by knowing the password to the file) either on 
iPhone, iPad, Mac desktop or PC laptop? 

[toc] | [next] | [standalone]


#11440

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 09:45 -0400
Message-ID<070820120945269780%nospam@nospam.invalid>
In reply to#11438
In article <5020e138$0$1736$c3e8da3$3a1a2348@news.astraweb.com>, Gary
<gary_w1@hotline.com> wrote:

> I have a text document which I use to keep track of my passwords, 
> logins, program registration codes, etc.
> 
> I am concerned about the havoc that could result from it getting into 
> the wrong hands, especially with the potential exposure of iCloud and 
> Dropbox services.
> 
> Does anyone know of a simple technique I can use to encrypt it such 
> that I could decrypt it (by knowing the password to the file) either on 
> iPhone, iPad, Mac desktop or PC laptop? 

create an encrypted disk image in disk utility and put the file there.

however, a much, much better way is use a password manager which is
designed just for tracking passwords, especially one which lets you
access it from multiple devices, such as 1password or lastpass.

[toc] | [prev] | [next] | [standalone]


#11443

FromHarald Hanche-Olsen <hanche@math.ntnu.no>
Date2012-08-07 18:23 +0200
Message-ID<pco628u8ye2.fsf@math.ntnu.no>
In reply to#11440
[nospam <nospam@nospam.invalid>]

>> Does anyone know of a simple technique I can use to encrypt it such 
>> that I could decrypt it (by knowing the password to the file) either on 
>> iPhone, iPad, Mac desktop or PC laptop? 
>
> create an encrypted disk image in disk utility and put the file there.

And use it on iDevices how?

> however, a much, much better way is use a password manager which is
> designed just for tracking passwords, especially one which lets you
> access it from multiple devices, such as 1password or lastpass.

Indeed. Strip (http://getstrip.com/) seems a good choice, with support
for iOS, OS X, Windows, Android (which makes you wonder if they haven't
got linux support in the pipeline). Moreover, they seem to be doing the
crypto right, which is not universally true of password managers:

  http://www.elcomsoft.com/WP/BH-EU-2012-WP.pdf

-- 
* Harald Hanche-Olsen     <URL:http://www.math.ntnu.no/~hanche/>
- It is undesirable to believe a proposition
  when there is no ground whatsoever for supposing it is true.
  -- Bertrand Russell

[toc] | [prev] | [next] | [standalone]


#11445

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 12:43 -0400
Message-ID<070820121243258955%nospam@nospam.invalid>
In reply to#11443
In article <pco628u8ye2.fsf@math.ntnu.no>, Harald Hanche-Olsen
<hanche@math.ntnu.no> wrote:

> >> Does anyone know of a simple technique I can use to encrypt it such 
> >> that I could decrypt it (by knowing the password to the file) either on 
> >> iPhone, iPad, Mac desktop or PC laptop? 
> >
> > create an encrypted disk image in disk utility and put the file there.
> 
> And use it on iDevices how?

he said either, not all, but a valid point. if he needs it on multiple
platforms, an encrypted dmg won't work, even if he doesn't mind the
hassles.

> > however, a much, much better way is use a password manager which is
> > designed just for tracking passwords, especially one which lets you
> > access it from multiple devices, such as 1password or lastpass.
> 
> Indeed. Strip (http://getstrip.com/) seems a good choice, with support
> for iOS, OS X, Windows, Android (which makes you wonder if they haven't
> got linux support in the pipeline). Moreover, they seem to be doing the
> crypto right, which is not universally true of password managers:
> 
>   http://www.elcomsoft.com/WP/BH-EU-2012-WP.pdf

1password and last pass do it right.

[toc] | [prev] | [next] | [standalone]


#11441

From"Douglas C. Neidermeyer" <sgt@arms.omega.faber.edu>
Date2012-08-07 10:34 -0400
Message-ID<jvr92f$i1h$1@news.albasani.net>
In reply to#11438
On 8/7/12 5:34 AM, Gary wrote:
> I have a text document which I use to keep track of my passwords,
> logins, program registration codes, etc.
>
> I am concerned about the havoc that could result from it getting into
> the wrong hands, especially with the potential exposure of iCloud and
> Dropbox services.
>
> Does anyone know of a simple technique I can use to encrypt it such that
> I could decrypt it (by knowing the password to the file) either on
> iPhone, iPad, Mac desktop or PC laptop?
>

PGP

-- 
The more is given, the less the people will work for themselves and the 
less they work, the more their poverty will increase.
                                      --Leo Tolstoy

[toc] | [prev] | [next] | [standalone]


#11449

FromJim Janney <jjanney@shell.xmission.com>
Date2012-08-07 18:07 -0600
Message-ID<ydn8vdqs0tl.fsf@shell.xmission.com>
In reply to#11438
Gary <gary_w1@hotline.com> writes:

> I have a text document which I use to keep track of my passwords,
> logins, program registration codes, etc.
>
> I am concerned about the havoc that could result from it getting into
> the wrong hands, especially with the potential exposure of iCloud and
> Dropbox services.
>
> Does anyone know of a simple technique I can use to encrypt it such
> that I could decrypt it (by knowing the password to the file) either
> on iPhone, iPad, Mac desktop or PC laptop? 

Wuala covers all those platforms and is at least theoretically safe from
cracking, since the server only sees your data after it's been
encrypted.

    http://www.wuala.com/

-- 
Jim Janney

[toc] | [prev] | [next] | [standalone]


#11456

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-08-07 22:36 -0400
Message-ID<jvsjc7$252$1@dont-email.me>
In reply to#11449
On 08-07-2012 20:07, Jim Janney wrote:
> Gary <gary_w1@hotline.com> writes:
>> I have a text document which I use to keep track of my passwords,
>> logins, program registration codes, etc.
>>
>> I am concerned about the havoc that could result from it getting into
>> the wrong hands, especially with the potential exposure of iCloud and
>> Dropbox services.
>>
>> Does anyone know of a simple technique I can use to encrypt it such
>> that I could decrypt it (by knowing the password to the file) either
>> on iPhone, iPad, Mac desktop or PC laptop?
>
> Wuala covers all those platforms and is at least theoretically safe from
> cracking, since the server only sees your data after it's been
> encrypted.
>
>      http://www.wuala.com/

You know, I think the are probably safe.  But I feel obligated to point 
out that it is _possible_ the app also passes the decryption key over to 
them.

-- 
Wes Groleau

     ASCII stupid question, get a stupid ANSI

[toc] | [prev] | [next] | [standalone]


#11467

FromPaul Sture <paul@sture.ch>
Date2012-08-08 11:01 +0200
Message-ID<vfm9f9-gs62.ln1@news1.chingola.ch>
In reply to#11456
On Tue, 07 Aug 2012 22:36:54 -0400, Wes Groleau wrote:

> On 08-07-2012 20:07, Jim Janney wrote:
>> Gary <gary_w1@hotline.com> writes:
>>> I have a text document which I use to keep track of my passwords,
>>> logins, program registration codes, etc.
>>>
>>> I am concerned about the havoc that could result from it getting into
>>> the wrong hands, especially with the potential exposure of iCloud and
>>> Dropbox services.
>>>
>>> Does anyone know of a simple technique I can use to encrypt it such
>>> that I could decrypt it (by knowing the password to the file) either
>>> on iPhone, iPad, Mac desktop or PC laptop?
>>
>> Wuala covers all those platforms and is at least theoretically safe
>> from cracking, since the server only sees your data after it's been
>> encrypted.
>>
>>      http://www.wuala.com/
> 
> You know, I think the are probably safe.  But I feel obligated to point
> out that it is _possible_ the app also passes the decryption key over to
> them.

The other point about Wuala is that it requires Java.  Given the number 
of security holes that have been found in Java, I don't really want to 
run it on every system.  Once Apple cease software updates for the 
versions of OS X which contain Apple's Java distribution, that could get 
worse.

This is already the case for Leopard,  Given the informed guesses in this 
newsgroup about likely dates that Apple stop issuing updates for Snow 
Leopard, it is something to be considered.

A reminder about Flashback:

<http://www.macrumors.com/2012/06/13/apple-updates-java-for-lion-and-snow-
leopard-in-sync-with-oracle/>

-- 
Paul Sture

[toc] | [prev] | [next] | [standalone]


#11476

FromJim Janney <jjanney@shell.xmission.com>
Date2012-08-08 16:14 -0600
Message-ID<ydnmx25qbe3.fsf@shell.xmission.com>
In reply to#11467
Paul Sture <paul@sture.ch> writes:

> On Tue, 07 Aug 2012 22:36:54 -0400, Wes Groleau wrote:
>
>> On 08-07-2012 20:07, Jim Janney wrote:
>>> Gary <gary_w1@hotline.com> writes:
>>>> I have a text document which I use to keep track of my passwords,
>>>> logins, program registration codes, etc.
>>>>
>>>> I am concerned about the havoc that could result from it getting into
>>>> the wrong hands, especially with the potential exposure of iCloud and
>>>> Dropbox services.
>>>>
>>>> Does anyone know of a simple technique I can use to encrypt it such
>>>> that I could decrypt it (by knowing the password to the file) either
>>>> on iPhone, iPad, Mac desktop or PC laptop?
>>>
>>> Wuala covers all those platforms and is at least theoretically safe
>>> from cracking, since the server only sees your data after it's been
>>> encrypted.
>>>
>>>      http://www.wuala.com/
>> 
>> You know, I think the are probably safe.  But I feel obligated to point
>> out that it is _possible_ the app also passes the decryption key over to
>> them.
>
> The other point about Wuala is that it requires Java.  Given the number 
> of security holes that have been found in Java, I don't really want to 
> run it on every system.  Once Apple cease software updates for the 
> versions of OS X which contain Apple's Java distribution, that could get 
> worse.
>
> This is already the case for Leopard,  Given the informed guesses in this 
> newsgroup about likely dates that Apple stop issuing updates for Snow 
> Leopard, it is something to be considered.
>
> A reminder about Flashback:
>
> <http://www.macrumors.com/2012/06/13/apple-updates-java-for-lion-and-snow-
> leopard-in-sync-with-oracle/>

As it happens, I'm running Snow Leopard with Java installed, but I have
Java turned off in Safari.  Other than running malicious applets, are
there any security holes I should worry about?

-- 
Jim Janney

[toc] | [prev] | [next] | [standalone]


#11458

FromBob Harris <nospam.News.Bob@remove.Smith-Harris.us>
Date2012-08-07 23:12 -0400
Message-ID<nospam.News.Bob-FD2BBA.23124107082012@news.eternal-september.org>
In reply to#11438
In article <5020e138$0$1736$c3e8da3$3a1a2348@news.astraweb.com>,
 Gary <gary_w1@hotline.com> wrote:

> I have a text document which I use to keep track of my passwords, 
> logins, program registration codes, etc.
> 
> I am concerned about the havoc that could result from it getting into 
> the wrong hands, especially with the potential exposure of iCloud and 
> Dropbox services.
> 
> Does anyone know of a simple technique I can use to encrypt it such 
> that I could decrypt it (by knowing the password to the file) either on 
> iPhone, iPad, Mac desktop or PC laptop? 

another vote for 1Password especially using DropBox.com to sync 
the encrypted password file that ONLY you have to decryption key 
for.

LastPass is also a good choice.

I've played with Both, but at the moment I'm favoring 1Password.

[toc] | [prev] | [standalone]


Back to top | Article view | comp.sys.mac.apps


csiph-web