Re: More on caching and logging



In article <290420071750025394%geefive@xxxxxxxxxxx>,
geefive <geefive@xxxxxxxxxxx> wrote:

In article <uce-299C07.19483729042007@xxxxxxxxxxxxxxxxxxxxxxxx>,
Gregory Weston <uce@xxxxxxxxxx> wrote:

The point is that this product doesn't have any real decryption
capabilities, nor does it self-elevate its permissions. It's just an app
that runs as the current user and extracts information that's already
readable to absolutely every other app you run under your account should
it choose to do so.

Read that again: It doesn't break any security that's in place. It
simply harvests information which is already insecure.

It says:

"Once the software is run it will extract
data from the Apple Keychain and system settings in order to provide
the examiner fast access to the suspect's critical information with as
little interaction or trace as possible."

Aren't keys encrypted?

The default behavior of the user's primary keychain is to unlock when
you log in to your account. This can be changed via the Keychain Access
application, but most people don't. The product we're talking about
relies on that reality to get at (some of) the information it gathers.
.



Relevant Pages

  • Re: Keychain Access/Entourage
    ... 0001HW.BDB65A0C003731DAF04076D0@news.microsoft.com, "Corentin Cras-Méneur" ... > Sometimes you can get that error message even when you ask the app to save ... It usually is related to problems in the Keychain itself. ... in the account settings for the account in question (Tools | ...
    (microsoft.public.mac.office.entourage)
  • Re: Application Flow / security issues
    ... You won't need a special service account. ... If the use case of the app is basically to have a user log in and then loop ... I just checked with corp. and if I want to do delegation I have to ask ... - You are using integrated windows auth in your web app ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: How good is Comodo Internet Security?
    ... Admin account + web browser + LUA token ... admin account opposed of running as iam now, which is JUST PURE admin level? ... While LUA gives added security, ... payload delivered by a buffer overrun (assuming the app was allowed to ...
    (comp.security.firewalls)
  • RE: POP3 Connector
    ... SBS server that you created during setup. ... Directory Users/Computer app, it will list the domain as one of the ... listed under the "email address" tab in the user container. ... > administrator account. ...
    (microsoft.public.windows.server.sbs)
  • Re: User Account Running at Application_end
    ... My app is running under 1.1. ... They will not give either account full permissions for 'security' reasons. ... Am I the only one who desires to compact a database periodically?? ... This routine works fine on another shared host. ...
    (microsoft.public.dotnet.framework.aspnet)