<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Self Decrypting Archives are BAD</title> <atom:link href="http://digitalbush.com/2009/03/31/self-decrypting-archives-are-bad/feed/" rel="self" type="application/rss+xml" /><link>http://digitalbush.com/2009/03/31/self-decrypting-archives-are-bad/</link> <description>Tales of a Tormented Software Developer</description> <lastBuildDate>Thu, 19 Apr 2012 15:22:59 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.2.1</generator> <item><title>By: Jack</title><link>http://digitalbush.com/2009/03/31/self-decrypting-archives-are-bad/comment-page-1/#comment-3126</link> <dc:creator>Jack</dc:creator> <pubDate>Sun, 24 Apr 2011 22:14:06 +0000</pubDate> <guid
isPermaLink="false">http://digitalbush.com/?p=388#comment-3126</guid> <description>So, you make some VERY good points, but I completely agree with &quot;Yes But&quot;.  SDA&#039;s are a nice to have specifically because of the lack of prevalence of people using GnuPG or PGP, etc.  The one thing I can&#039;t even figure out is what, exactly you are attributing to &quot;laziness&quot;?  Lack of security isn&#039;t always because of laziness, rather, because of lack of education.  I&#039;ve known brilliant, highly educated people who are not experts in security.  So in your assessment, we just throw our hands up and send sensitive information them in the clear?  I doubt that&#039;s what you&#039;re trying to convey.You are clearly very educated with regard to security, and as such, your opinions better serve the ~uneducated without the added negativity (frustrating as it can be).  Best to assume that when you&#039;re posting to the net that you aren&#039;t always talking to people that you&#039;ve had to say the same thing to nine times.Imagine if you went to the doctor and he had the attitude that your lack of ability to self diagnose was incredibly lazy of you.  I&#039;d be pissed too.</description> <content:encoded><![CDATA[<p>So, you make some VERY good points, but I completely agree with &#8220;Yes But&#8221;.  SDA&#8217;s are a nice to have specifically because of the lack of prevalence of people using GnuPG or PGP, etc.  The one thing I can&#8217;t even figure out is what, exactly you are attributing to &#8220;laziness&#8221;?  Lack of security isn&#8217;t always because of laziness, rather, because of lack of education.  I&#8217;ve known brilliant, highly educated people who are not experts in security.  So in your assessment, we just throw our hands up and send sensitive information them in the clear?  I doubt that&#8217;s what you&#8217;re trying to convey.</p><p>You are clearly very educated with regard to security, and as such, your opinions better serve the ~uneducated without the added negativity (frustrating as it can be).  Best to assume that when you&#8217;re posting to the net that you aren&#8217;t always talking to people that you&#8217;ve had to say the same thing to nine times.</p><p>Imagine if you went to the doctor and he had the attitude that your lack of ability to self diagnose was incredibly lazy of you.  I&#8217;d be pissed too.</p> ]]></content:encoded> </item> <item><title>By: Yes But</title><link>http://digitalbush.com/2009/03/31/self-decrypting-archives-are-bad/comment-page-1/#comment-2945</link> <dc:creator>Yes But</dc:creator> <pubDate>Mon, 19 Apr 2010 17:51:20 +0000</pubDate> <guid
isPermaLink="false">http://digitalbush.com/?p=388#comment-2945</guid> <description>Excellent points.  There&#039;s just one problem -- security is not binary.  There is more security with an Self-Decrypting Archive than a plain-text email.  That security is not merely an illusion, even if it is far less effective than tried-and-true encryption techniques.In a cost-benefit analysis when dealing with someone who you will have to walk through the entire download, install, key generation, password selection, and any troubleshooting vs. simply ordering them to execute a Self-Decrypting Archive (SDA) for a single communication or otherwise seems to favor the SDA option.  It&#039;s more secure than a plain-text email, less secure than GnuPG&#039;s full suite.To claim it is &quot;bad all around&quot; fails to appreciate the nuances here.  There are certainly instances when I&#039;d rather send a rare sensitive communique to persons who would have no other use for encryption software.  Asking them to install the full suite, generate a key, and password for one message seems beyond ridiculous.Unfortunately, the SDA is the only solution I&#039;ve stumbled upon.  There is nothing else as simple out there.  However, if you have that solution, _please_ share it because I&#039;ve been searching for 2 weeks now.You might argue that there are many means of bypassing the limited security SDA&#039;s provide but that&#039;s like arguing you shouldn&#039;t use a simple doorknob lock because bank-vault doors are far more effective.  An interested party still has to exert some effort to bypass a doorknob lock and most people aren&#039;t capable of doing so (the vast majority of people can&#039;t pick a lock) therefor we still use simple doorknob locks even though we know they won&#039;t protect us from any hardcore attacks (just watch any horror movie).In other words, most people won&#039;t bother or can&#039;t bypass a simple lock, the same could be said of SDA.The problem is, of course, is some people who&#039;d use an SDA may not understand the actual level of security they are getting but that is a whole other discussion.</description> <content:encoded><![CDATA[<p>Excellent points.  There&#8217;s just one problem &#8212; security is not binary.  There is more security with an Self-Decrypting Archive than a plain-text email.  That security is not merely an illusion, even if it is far less effective than tried-and-true encryption techniques.</p><p>In a cost-benefit analysis when dealing with someone who you will have to walk through the entire download, install, key generation, password selection, and any troubleshooting vs. simply ordering them to execute a Self-Decrypting Archive (SDA) for a single communication or otherwise seems to favor the SDA option.  It&#8217;s more secure than a plain-text email, less secure than GnuPG&#8217;s full suite.</p><p>To claim it is &#8220;bad all around&#8221; fails to appreciate the nuances here.  There are certainly instances when I&#8217;d rather send a rare sensitive communique to persons who would have no other use for encryption software.  Asking them to install the full suite, generate a key, and password for one message seems beyond ridiculous.</p><p>Unfortunately, the SDA is the only solution I&#8217;ve stumbled upon.  There is nothing else as simple out there.  However, if you have that solution, _please_ share it because I&#8217;ve been searching for 2 weeks now.</p><p>You might argue that there are many means of bypassing the limited security SDA&#8217;s provide but that&#8217;s like arguing you shouldn&#8217;t use a simple doorknob lock because bank-vault doors are far more effective.  An interested party still has to exert some effort to bypass a doorknob lock and most people aren&#8217;t capable of doing so (the vast majority of people can&#8217;t pick a lock) therefor we still use simple doorknob locks even though we know they won&#8217;t protect us from any hardcore attacks (just watch any horror movie).</p><p>In other words, most people won&#8217;t bother or can&#8217;t bypass a simple lock, the same could be said of SDA.</p><p>The problem is, of course, is some people who&#8217;d use an SDA may not understand the actual level of security they are getting but that is a whole other discussion.</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)
Database Caching 4/9 queries in 0.004 seconds using apc

Served from: _ @ 2012-05-21 12:00:44 -->
