List Info

Thread: PGP Disk version 6.02




PGP Disk version 6.02
user name
2006-10-20 16:09:13

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

> 3d. Re: PGP Disk version 6.02
> Posted by: "Robert J. Hansen" rjh%40sixdemonbag.org">rjhsixdemonbag.org
>
> If we're talking about PGP 6.5.8-CKT, which we probably are,
> then you're not in luck.
>; Imad has made sure that it will install on Windows XP
> machines.
.
.
can verify that ckt versions 8 and later, with pgp disk,
do work well on windows xp,
.
that said,
.
and taking into account,
that i'm a firm believer that the ckt versions
are functionally better and easier to use
than any other pgp versions,
.
i still must say, that there is no reason to use ckt's pgpdisk
when truecrypt is available, and incomparably better,
(not just better than 6.5.8 pgpdisk,
but also better than 9.x pgpdisk),
.
some unique advantages of truecrypt:
[1] hidden volume
[2] choice of encryption algorithm, and sequential encryption
[3] ability to use keyfiles
[4] crossplatform (windows / linux)
[5] alerting when a proposed container size exceeds what can
safely be encrypted using a single key
(see truecrypt faq here: http://www.truecrypt.org/faq.php)
.
[ i don't know what the size is where this becomes a problem,
but practically,
it might be something to worry about
with increasingly larger hard drives,
*if* truecrypt issued a warning
against a particular proposed size,
while pgp allowed for who;e-disk encryption exceeding this size,
.
again,
i don't know of a *specific* practical vulnerability situation]
.
.
there is one other compatibility annoyance
with continuing to use ckt with current gnupg versions:
.
ckt generates rsa v4 keys that are *both* sign and encrypt
for the primary and the subkey,
.
gnupg does *not* allow for such a ckt-generated signing subkey
to 'cross-certify' its primary key,
and as a result,
will give warnings when such a subkey is used for signing,
.
this is compounded by the fact that gnupg insists
on signing with the subkey by default,
(and of all the gnupg front-ends,
only gpgshell (so far) allows for
selecting the primary signing key to be used
rather than the signing subkey,)
.
this message will be clearsigned using gpgee,
using both my v3 and v4 keys,
and even though the following line is in my gpg.conf,
default-key 0x5AA20C866A589A97!
the signing subkey
is still selected by all the gpg4win front ends,
.
so, if anyone is going to use ckt,
i recommend generating the keys in gnupg,
and then importing to ckt.
.
.
vedaal
(hoping that this clearsig makes it through yahoo )
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (MingW32)
Comment: Acts of Kindness better the World, and protect the Soul

iQIVAwUBRTj0MqyhY/YEre4gAQhqThAAg//WEXFIUUpX9rN9eY7C/kuq9fvaS8kb
wYSFxFFpyRZTsdlVGWe+fyRsMf3KAKb+Z+klXwnmwkHTjS/qgLwy38zqUwkZXgMT
cjX4fC4+SBSgmLDV8GCtQqqyg0zW4FXtlK0D6bRnIErzQfCKFQi6msrts++cKxXU
ek/h1hTeAxZwIdgMKzcJBDe/axJcc5qD/dCyIe+RP208G1a84hnp6nZLhYe5XL1h
nbmqKQp8n40azDlsM4SUqGOC5T8ikSRMA4+R6BRZO1yJvx0wzPl689kX6x32fAYB
zvaCPN3ESSrTyKQDoFsKZblpyOkb1hKVPEtCclX4RL1PUVhnU20n335caWUltycN
BPo7fi7tUWTsqxFbwxo/C76D8xy9HNXiEKATO0ENARZMFT4DZYSRJGpsbPh9xBiv
8x+AJlTBV7H/ed5D7MmsHlk5YIDxI6XJtGxHghRh2MrtSne3f2gCt3lNfrPE/tyj
ig7wLQhP6vCDIzi5ImiEO/q4alrmCcWppjAYgQqa63nQK/YHn+srD9/1fO/maJJE
8HZEk5TIc3jf9qioIFBRn1QgcnSzTRaD8ehxBNQxQE74bawhcCTelXtzxwOLKr3;E
X6qJzbBho7r0yjMyArU/MVivQdRWWZwr/eATrbsFAPD0gEO8H7l4ShfpXfLL8k0m
uiSVQTal/XeJARUDBQFFOPQzagWgt4UwbSUBCMHIB/9c6G0TLGAVlVzWNF1D9bMO
gQi9mDS0c9HBk/7/7f912muBLD1hji0MBsbuqO2fCHGGX/qRjMF1G4obGOFHgJ2X
vuSo7bpBVOS3fUJBnXUNGb6EJrQ7Rw1EhxUmLhP5xNM1V9H+IA7eOe3ZTod616cy
wzfYOYFPGQc3F6MUvsM/ti/KKg22xA7BbwDQc/Ellhu/o7xMcF03Fw/uehog/qYU
frfx0wQpCkXies5KDo03lqljXUf7cltOQ2O0+0QFH8gVG30KV9bIA8JrtvRKQ3My
zZU+3FCjw6qq0G4QWImmZ2ai00gMVFTHQ+ZGLmEaB6N9siNPyloQ1Z25rLm3gh/X
=Edzd
-----END PGP SIGNATURE-----

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

__._,_.___
.

__,_._,___
PGP Disk version 6.02
user name
2006-10-20 19:12:11

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

vedaal nistar wrote:
> can verify that ckt versions 8 and later, with pgp disk,
>; do work well on windows xp,

With great respect, vedaal, no, you can't.

You can say that it works well _for you_, _on your system_. But that's
not quality assurance testing. Formal QA testing will run a program on
lots of different versions of a system, with all manner of different
things installed. Some will be set up with this feature, some will have
that .DLL removed, some will have this hardware, some will have that
hardware...

QA testing, done right, is very hard and very time consuming. It's not
at all unusual for QA testing to take more time and money than
developing the software.

The CKT builds have had no real QA testing, as near as I can tell. It's
one of the reasons why I lack faith in it. Just because it works well
for you is fairly weak evidence that it will work well for me. Nor is
there any database of systems it works well on and systems it bombs on,
so that I can take a look at it and see if my system is on the "works
well" list.

(ObDisclosure: I got my start in the software industry doing QA for MCI.
Hated hated hated hated the job. Easily the second-worst job in IT,
right after helpdesk. Low pay, long hours, no respect from Management...)

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iQEcBAEBCAAGBQJFOR+;LAAoJELcA9IL+r4EJRtgH/0VN4AXw91yPFD0v5XKS7ffN
HuqEU/XUWnbfUoyqFyLJim/VcmjE8DVxQlVjQNYDVKpy7AWppsHms+j7qc/xcCK2
9SO4DLCmO9H73E0epueh4YnaGBJrPvuEqm3SShrTpuQZQ5f9HeB2DSNBHOgpBP99
mQqOeXXsryRuIH22gImsqUdQmsmHms8RHjj41jo8fPuShgIiOpPZdoGanTT6XuWh
NTlnYstFFAbAma/sMV7aTBWQm9Im7OV87U5xojWiKEbpDETeZ8QZHXtViHX0DYQc
MDICsdb3L/3vDW+IBlvGGqDzpZFXTb1GPR/dj2A0cucc8VEAxgj17w1ER2V/G+0=
=NKQS
-----END PGP SIGNATURE-----

__._,_.___
.

__,_._,___
[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )