home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.compression:4593 sci.crypt:6704
- Newsgroups: comp.compression,sci.crypt
- Path: sparky!uunet!haven.umd.edu!darwin.sura.net!Sirius.dfn.de!news.DKRZ-Hamburg.DE!rzsun2.informatik.uni-hamburg.de!fbihh!bontchev
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Subject: Re: ARJ "Security Envelopes" Broken
- Message-ID: <bontchev.726852983@fbihh>
- Sender: news@informatik.uni-hamburg.de (Mr. News)
- Reply-To: bontchev@fbihh.informatik.uni-hamburg.de
- Organization: Virus Test Center, University of Hamburg
- References: <1993Jan9.065934.4930@leland.Stanford.EDU> <bontchev.726782688@fbihh> <1993Jan11.232731.9624@umr.edu>
- Date: 12 Jan 93 15:36:23 GMT
- Lines: 30
-
- mcastle@cs.umr.edu (Michael R Castle) writes:
-
- > When ARJ first came out, I sent mail to Rob mentioning the problems with
- > exporting pkzip and advising that he may want to look into the legalities
- > of his using encryption in exportable software. In his response, he
- > indicated that he was just using simple xoring (which he expected to be
- > easily broken). The _ONLY_ reason for encryption was to keep a casual
- > user from accidently private data. Stopping crackers who are trying to
- > break into archives was not the point behind adding encryption to arj.
-
- Yes, I understand that - it is mentioned in the documentation. But,
- first, the export restrictions didn't stop anyone from exporting PKZIP
- (hey, they even don't have the version without encryption in USSR and
- Bulgaria), second, it seems that PKWare has obtained license to export
- their program to almost any country (except a few from a restricted
- list), and third, the encryption code for Info-ZIP is freely available
- on the ftp sites... This algorithm might not be strong enough from the
- cryptographic point of view (I have yet to see a serious cryptanalysis
- of it), but it is at least not as trivial to break as the algorithm
- used in ARJ...
-
- OK, maybe this discussion belongs to sci.crypt...
-
- Regards,
- Vesselin
- --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-