Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-27-2007, 06:31 PM
Zak
Guest
 
Posts: n/a
Default Viewing/opening file sent by secure method

Assume users are on On XP:

Suppose a document file (either a PDF file or TXT file) is sent by email
from one company to another using a secure method to encrypt the file
such as using WinZip with AES.

The ZIP file is received on a PC which is in a shared area and the PC
could be accessed overnight by other people.


QUESTION: How can the recipient open or view the file WITHOUT having to
later delete swap files, temp files, empty recycle bin, erase disk
areas, etc. The recipients in my case are non-tecnical and this
housekeeping will seem like a lot of new hoopla.

QUESTION: Is there an app which will decrypt a WinZip file but not
leave a trail of information?

QUESTION: Perhaps using a floppy or a CD to hold a Winzip-compatible
tool such as 7-Zip would work ??? Any suggestions?

QUESTIONS: Finally what about viewing the TXT or the PDF file that was
in the ZIP? Text and PDF viewers on the hard drive will probably create
temporary files also on the hard drive. Is there a floppy based PDF
viewer? Or a read-only PDF viewer which sits on a CD?


++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++
For ref: Notes on encryption safety (Winzip 10 help text).


EXTRACTING A FILE

If you extract an encrypted file and then delete the file, it may be
possible for someone to later "undelete" the file using file recovery
software or the Recycle Bin.

------

OPENING OR VIEWING A FILE

When you open or view a file from an archive (e.g., by double clicking
it), WinZip must extract the file to a TEMPORARY LOCATION so that the
associated program can open it. If you subsequently CLOSE WINZIP
without first closing the program that is using the file, WinZip may not
be able to delete the temporary copy of the file. Thereby leaving it on
disk in unencrypted form.

Furthermore, the ASSOCIATED PROGRAM may also make one or more BACKUP
COPIES of the decrypted file, and WinZip will not be able to delete
these.

In addition, as described above, it may be possible for someone to later
RECOVER DELETED FILES using file recovery software or the Recycle Bin.

--------

MEMORY AND PAGE SWAP FILES

After adding or extracting encrypted files, some or all of the
unencrypted file contents may remain in your computer's MEMORY or the
PAGE SWAP FILES on disk. A malicious user may be able to retrieve this
unencrypted information.
WinZip does not encrypt Zip file comments or, as described above,
information about encrypted files such as their names, dates, etc. Any
user with access to the Zip file can view this information without a
password.

++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++


x-posted to relevant groups

Reply With Quote
  #2 (permalink)  
Old 02-28-2007, 08:58 AM
Abut
Guest
 
Posts: n/a
Default Re: Viewing/opening file sent by secure method

On Feb 27, 7:31 pm, Zak <d...@nomail.invalid> wrote:

> Suppose a document file (either a PDF file or TXT file) is sent by email
> from one company to another using a secure method to encrypt the file
> such as using WinZip with AES.
>
> The ZIP file is received on a PC which is in a shared area and the PC
> could be accessed overnight by other people.
>
> QUESTION: How can the recipient open or view the file WITHOUT having to
> later delete swap files, temp files, empty recycle bin, erase disk
> areas, etc. The recipients in my case are non-tecnical and this
> housekeeping will seem like a lot of new hoopla.
>
> QUESTION: Is there an app which will decrypt a WinZip file but not
> leave a trail of information?

<snip>

I suggest you use PGP or GnuPG instead. These applications have been
designed to eliminate, as far as possible, the vulnerabilities you
mention.

MT


Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Viewing/opening file sent by secure method Zak alt.computer.security 1 02-28-2007 08:58 AM
Corrupt NTFS filesystem Citizen Bob alt.comp.hardware 144 11-11-2006 07:38 PM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 10-19-2005 04:37 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 08-30-2005 04:26 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 07-31-2005 04:25 AM


All times are GMT. The time now is 03:40 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45