Main Menu
Network
Sponsor
Top 10 Sites
Partners
|
|
| | Analysis of the WinZip Encryption Method | | Description | WinZip is a popular compression utility for Microsoft Windows computers, the latest version of which is advertised as having "easy-to-use AES encryption to protect your sensitive data." We exhibit several attacks against WinZip's new encryption method, dubbed "AE-2" or "Advanced Encryption, version two." We then discuss secure alternatives. Since at a high level the underlying WinZip encryption method appears secure (the core is exactly Encrypt-then-Authenticate using AES-CTR and HMAC-SHA1), and since one of our attacks was made possible because of the way that WinZip Computing, Inc.~decided to fix a different security problem with its previous encryption method AE-1, our attacks further underscore the subtlety of designing cryptographically secure software | | OS | | | Author | | | Submitted | 2005-10-13 23:19:34 by DiMan | | File size | 0.66mb | | Downloads | 874 (1 downloads/day) | |
|
|
|

InterJOB.su
|