RE: Is it possible to read encrypted logs with helper programs without a password?
The assumption is that the encryption is secure and that is not possible.
That said, the source code of Patchou's implementation is unpublished and hasn't been extensively reviewed by others, unlike Open Source cryptographic software. Implementation mistakes in cryptography are easy to make (e.g. predictable sources of entropy) and can greatly weaken an otherwise strong algorithm. If present and correctly exploited, small oversights often reduce the time required for a successful brute force attack from hundreds of years it should take in theory, to hours or minutes in practice.
If any such weakness (or intentional backdoor) exists in the log encryption, it is presently unknown.
This post was edited on 03-28-2007 at 09:32 PM by Adeptus.
|