4 ms·
Looking over the source code, this doesn't really look secure. A few notes: 1. Any decryption key which is shorter than the length of the encrypted data must b
by argusdusty 14y ago
Looking over the source code, this doesn't really look secure. A few notes:
1. Any decryption key which is shorter than the length of the encrypted data must be fake. This forces fake decrypted data to be the same length as the real decrypted data, which is impractical for large files.
2. There's no verification on any key, and it's quite trivial to produce fake keys, so should the 'government' want to claim you had illegal data, all they would have to do is produce their own 'fake key' corresponding to said illegal data.
3. Passwords are essentially random data - impossible to memorize. You'll have to keep them on your computer somewhere, and given their unusual nature in relation to other files, it would be pretty easy to do a search for them.
I'd advise sticking to hidden volumes on TrueCrypt for now.
- lucb1e 14y ago#2 would be the same as having the government claim they found an incriminating file on your harddrive which was never there. Still though, interesting point.