由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
PDA版 - NSA凶猛,试着做了一个加密的笔记APP,童鞋们给点意见
相关主题
lastpass被黑了,用的人赶紧去改密码吧 (转载)android的factory reset到底指什么。。。
Win 8.1 Device Encryption is enabled by default有人整过android tablet encryption 吗?
安卓root了就不能encrypt device了?1+不能做device encryption
HP touchpad wi-fi 上网问题Calif. bill would ban fully encrypted smartphones
NSA已经破解了主要的加密协议。Moto X pure很慢
老中在dropbox里都放啥?第一个国货手机,有点失望
NSA避免再爆丑闻,停止了加密软件Truecrypt的开发 (转载)使用edu邮箱可使dropbox扩容到最高16G
Shadowsocks 翻墙教程IPHONE的GPS TRACKING闹大了
相关话题的讨论汇总
话题: encryption话题: passwords话题: app话题: server话题: nsa
进入PDA版参与讨论
1 (共1页)
m*****9
发帖数: 12
1
Appstore url: http://tinyurl.com/l7ymphb
APP有记文本、照相笔记、限时分享等功能。
如果觉得有用的话在appstore那里给点好评。做个APP还蛮辛苦地,先谢过啦。
p***c
发帖数: 5202
2
怎么知道你不是NSA的双料间谍,来套取我们地下党的密电码?
坚决抵制。。。。哈哈
开玩笑,等会儿下下来试试
ra
发帖数: 827
3
The problem with encryption is that people often chose weak passwords.

【在 m*****9 的大作中提到】
: Appstore url: http://tinyurl.com/l7ymphb
: APP有记文本、照相笔记、限时分享等功能。
: 如果觉得有用的话在appstore那里给点好评。做个APP还蛮辛苦地,先谢过啦。

y*******d
发帖数: 1765
4
pwd and encryption key are totally different things...

【在 ra 的大作中提到】
: The problem with encryption is that people often chose weak passwords.
r****n
发帖数: 496
5
In such applications, encryption keys are derived from passwords directly or
indirectly, so the entropy in encryption keys depends on passwords, where
do you get extra entropy? Another secete?
In interactive communcation, there are protocols to derive strong encryption
keys from weak passwords, but as far as I know, this cannot be done for non
-interactive communication, e.g. storage.

【在 y*******d 的大作中提到】
: pwd and encryption key are totally different things...
m*****9
发帖数: 12
6
Encryption key is based on a combination of user's password and a
random string created on the server side. Password based brute-force attack
doesn't work if an attacker only has access to the encrypted data.
r****n
发帖数: 496
7
This random string is essentially another password, it makes it more
difficult to some attackers, but this random string will have to stored on
both client and server machines.So for NSA, if they can get your data from
the server, then why can't they also get this random string?
Sorry I am nitpicking, this is pure technical discussion.
One thing to make it a little more secure is to store your random string on
another server, maybe even from different ISP, or even different country, e.
g. one server in US, one server in China.
A more advanced scheme is to do something like secure sharing on top of
encrypted data, so that nothing is revealed without getting enough shares.

attack

【在 m*****9 的大作中提到】
: Encryption key is based on a combination of user's password and a
: random string created on the server side. Password based brute-force attack
: doesn't work if an attacker only has access to the encrypted data.

1 (共1页)
进入PDA版参与讨论
相关主题
IPHONE的GPS TRACKING闹大了NSA已经破解了主要的加密协议。
touchpad怎么设置网络啊老中在dropbox里都放啥?
贴个Sprint Photon 4G的wifi tether的方法(非ad-hoc)NSA避免再爆丑闻,停止了加密软件Truecrypt的开发 (转载)
Touchpad CM7 很不稳定Shadowsocks 翻墙教程
lastpass被黑了,用的人赶紧去改密码吧 (转载)android的factory reset到底指什么。。。
Win 8.1 Device Encryption is enabled by default有人整过android tablet encryption 吗?
安卓root了就不能encrypt device了?1+不能做device encryption
HP touchpad wi-fi 上网问题Calif. bill would ban fully encrypted smartphones
相关话题的讨论汇总
话题: encryption话题: passwords话题: app话题: server话题: nsa