3 ms·
It seems like a decent list of recommendations to me. If you follow all recommendations you're way ahead of the curve compared to what I've seen, but I've most
by cryptarch 9y ago
It seems like a decent list of recommendations to me.
If you follow all recommendations you're way ahead of the curve compared to what I've seen, but I've mostly seen small IT shops.
I do recall passworded ZIPs being easy to crack, that might be better replaced with a PGP-based alternative.
- tptacek 9y agoIt's dangerous to rely on password-protected ZIPs. The default ZIP implementations use an 1990s amateur cipher that cryptographers have been cracking for sport for decades. There's a ZIP standard for authenticated AES, but you have to use a high-quality ZIP implementation (like 7z) to get it, and most people don't have special ZIP software installed. Don't use password-protected ZIPs.
- voltagex_ 9y agoHey thanks for this - I didn't realise the "default" was so weak for ZIP. It's almost worth a HN post in itself, but I can't find a good reference to link to. 1: http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.49.2468 http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.49.2... (PDF maybe available via FTP?) 2: https://security.stackexchange.com/questions/5447/how-secure-is-a-windows-password-protected-zip-file https://security.stackexchange.com/questions/5447/how-secure...
- unstatusthequo 9y agoApparently you haven't had to crack any recently. As an attorney with infosec certification, I can tell you that in my world, AES ZIPs are just as practically impossible to crack as you'd guess.
- tptacek 9y agoYou're not reading what I wrote carefully enough. I'm not suggesting that AES-encrypted ZIPs are especially easy to crack. I'm saying that on most platforms, AES-encrypted ZIPs aren't what you get: you get ZIP 2.0 encryption.
- a3camero 9y agoLawyers generally take physical security seriously but rarely give digital security much thought. They're often working on their own (somewhere between 1/4 to 1/2 of lawyers are independent/very small firm in Canada/US). This means they don't have the time, expertise or money to invest in knowing what to do or how to do it. But I've found they usually do want to know and that was the reason for this presentation. This isn't a list of the best things to do, it's a list of some practical steps that can make things better. But ultimately the right level of security depends on the importance of the client communications. Some things are fine to do as Google Docs and other things you'll want to do with in-person meetings where no phones are allowed.