Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Friday, February 23, 2007

PGP 9.6 beta: full support for Vista!


I've been notified late at night yesterday: at last, after all that anger and impatience from us users, I must admit that the PGP team did a really nice job. PGP 9.6 beta with support for windows Vista is out and it works like a breeze. Here is the link where you can subscribe to the beta testing till the end of next march. Cannot say if then the final version will be there, or a beta 2. Anyway that's good news!

Sunday, February 18, 2007

TrueCrypt 4.2a on Vista: DON'T USE!


I said in a previous post that despite the advice from the author I was keeping using TrueCrypt on Vista, but I have now to update my comments urgently. As long as you just read files or execute them from an encrypted TrueCrypt volume on Vista, everything's fine. I'm talking about files written previously under windows XP. But as soon as you try to write to it, save data to the volume , you'll get data corruption , unreadable files, also impossible to delete. SO WAIT FOR THE NEXT VERSION BEFORE YOU USE TRUE CRYPT ON VISTA!

the author's link

ps: also saving from a dialog box make appear the same TrueCrypt volume mounted on 2 bloody drive letters, instead of just the one you chose.

ps: also saving from a dialog box make appear the same TrueCrypt volume mounted on 2 bloody drive letters, instead of just the one you chose.

don't get me wrong: TrueCrypt is a fantastic program that I've used for a long time under windows XP. Here is a link to the page where the author announces future features of TrueCrypt.

Thursday, February 15, 2007

PGP for Vista? not yet!

for those of you desperately waiting for a compatible version of PGP with Windows Vista, here is a thread of angry customers. Since Vista was already released to corporate users back in November 2006, imagine companies who subscribed to PGP services for years and must suddenly decrypt all their sensitive stuff, remove keys from email clients, or renounce to use the new OS. It's a real shame. These guys, like the ones from Creative Labs for instance, who still provide beta drives for their sound cards, have had months to get ready, and they're not. These guys mean than beta 1, beta 2, RC1, RC2, and RTM in November was not enough to get some kinda work done.
http://forums.pgpsupport.com/viewtopic.php?p=30542&sid=ee4666f408cd240aad286e5b418d75ee

Monday, January 29, 2007

SimpLite - freeware IM encryption


Actually this program concerns many of us users running instant messaging programs on our desktops. Let's just take an example: MSN, sorry Windows Live Messenger. Are you aware that your conversations are transmitted in clear through Microsoft servers? It is not a secret: the guys at Microsoft recognize that. I read it a year ago in a comparative test between MSN messenger and Windows Messenger. It sounds like I'm going to advertise a product, but I'm not. I'll speak here about it just because I like it. This product, in it's freeware version, is called SimpLite (developed by SecWay). This freeware version actually includes several programs, depending on the protocol that you want to use in instant messaging:

- SimpLite for ICQ/AIM
- SimpLite for Jabber (Google Talk protocol)
- SimpLite for MSN (works with Windows Live Messenger 8)
- SimpLite for Yahoo

All you have to do is install the version that meets your needs, launch it, create a key that will authenticate you on the network, and you're done. To achieve that, SimpLite puts a socks proxy server between your computer and Microsoft Messenger service. Now see what happens when a friend of yours has done the same and get in touch with him; really cool. Just privacy OK?

Now you can always go for the commercial version, called SimpPro, that has all protocols in one program, and stronger encryption, plus the ability to also encrypt file transfers. OK Skype does that already for free in his chat interface. But Skype does not allow authentification, and its chat interface doesn't match MSN. So I'd rather go for an IM solution that includes MSN + SimpPro.

One last thing, Secway is french, and that's good news !

Sunday, January 21, 2007

TrueCrypt: virtual encrypted drives


time to speak a bit more about TrueCrypt. This piece of OpenSource software appears like one, or may be THE competitor of PGP. It does not offer the ability to encrypt files, nor does it allow email encryption, so what does it do, that PGP does too? It can create virtual encrypted drives in 2 clicks using the most sophisticated pieces of algorithm: AES 256, TwoFish, Serpent... so what's the point if PGP does it too? PGP is not free,here is the link. In other terms it means that you can use the freeware part of PGP for file encryption and manual email encryption, and get the missing features, the ones that you did not pay for, with True Crypt. There are differences in the way both programs encrypt drives, but that might not give an edge to PGP over True Crypt. I might make a comparative later in this blog.

ps: I just noticed that as a respomse to true Crypt, PGP in it's last version 9.52 added 2 more algorithms as a new option in disk encryption. It used to be restricted to AES 256 there.

Wednesday, January 17, 2007

SSL stuff: part II


here are a couple of places where you can apply for an SSL certificate. You'll find there both commercial and free solutions:

Verisign
Thawte
Geotrust
Abylonsoft
CAcert
Entrust

I personally use a Thawte one, and I'm quite happy with it. But feel free to review the content of the links that I mentioned.

please check this article from Netcraft on the SSL certificate market, really interesting.
here is also a link to a pdf document from Geotrust.


SSL stuff: part 1

privacy matters. For those of you who might still ignore it, every single piece of mail that you send or receive, even when you're using an email client like Mozilla Thunderbird or Outlook Express, leaves a copy on the server where your mailbox resides. You cannot avoid this, and deleting the messages in the web interface of an email client does not change anything, as some hidden copies will remain anyway. Google admitted it not so long ago for gmail. They're just honest enough to admit it, but may be not enough when they pretend to do it for backup security reasons. Well, once you've deleted a message from a mail server, you don't expect it to be backed up or do you?
Anyway the only workaround to this privacy mess is called SSL (Secure Sockets Layer), an encryption protocol developed by Netscape to provide enhanced security whenever you connect
to your bank account website for instance, via HTTPS, or when you send mail. For web site SSL, most of the time you'll be automatically using the site certificate, although some sites will require that you authenticate yourself with your own certificate. It's just the same for mails. Once you've subscribed to an email ssl certificate, you'll be able to sign your mails, and as soon as you'll get a mail from someone using a certificate too, you'll be able to encrypt the next message to this person using his public key. And only this person, who authenticated you because you signed your message, will aslo be able to decrypt it. Certificates remain on computers, imported in your email client. Which means that the copy of a message remaining on a web server is perfectly unreadable. Got it?

Tuesday, January 16, 2007

cloaking versus encryption

"Could invisibility beat encryption?"

check that link to an article
from The Register. Got it this morning
in the newsletter I got from them, haven't read it yet.
So far I've used True Crypt on my PC, whenever I wanted to conceal anything from other's eyes, like my precious Windows EFS certificate, the one that cost me almost all my data a few months ago ( that poor piece of cert just got corrupt...). All this to say that when it comes to serious stuff, there's nothing like True Crypt. It is bloody fantastic.Once again if you haven't found it yet in our favorite links, here is the link