Page 1 of 1
create password
Posted: Tue May 03, 2005 9:39 pm
by sathiya21

i want create password to protect my special folder at my
home desktop.anyone any idea?
Re:create password
Posted: Tue May 03, 2005 9:54 pm
by AR
What is a "special folder"? On Windows XP, just right click>Properties click "Advanced" then tick "encrypt this folder", the folder will be encrypted using your account password.
Re:create password
Posted: Wed May 04, 2005 11:04 am
by rich_m
but it does'nt block the adminstrator, right?
Re:create password
Posted: Wed May 04, 2005 5:18 pm
by AR
Encryption blocks everyone, the Administrator can see the files but can't open them as they need the user's password to decrypt them. The folder permissions are different and can be bypassed however.
Re:create password
Posted: Thu May 05, 2005 1:15 pm
by Ushma
But then again, an administrator could easily install a keylogger on his/her own system, obscure it, and pick up the password next time you type it. At which point reading the contents of the folder becomes rather easy.
Re:create password
Posted: Mon May 09, 2005 12:44 am
by Solar
You cannot "defend" your data against someone who is Admin on your system (or has physical access to it). If you don't trust the admin, don't put sensitive data on the system.
Re:create password
Posted: Tue May 17, 2005 9:28 am
by TheUnbeliever
Administrator could just change the user's password, then use that, or grab the SAM database and run L0phtcrack, John the Ripper or something like that.
If you really don't trust the administrator, create an encrypted partition on a USB drive and store data on that. Use PGP, if you really wish.
Re:create password
Posted: Tue May 31, 2005 12:43 am
by Solar
TheUnbeliever wrote:
If you really don't trust the administrator, create an encrypted partition on a USB drive and store data on that. Use PGP, if you really wish.
And still be aware that the Admin can install keysniffers, provoke coredumps and read the password from that, and a wide variety of other hacks.
You can't protect your data from a malicious admin, period. Even if you take your encrypted USB stick home, a skillful Mallory will have sniffed your keyword and copied the cyphertext. You have been hacked.
Re:create password
Posted: Wed Jun 01, 2005 4:11 pm
by mystran
Boot from a CD into your personally "carry-with-me" OS installation, and use a USB memory stick for your home directory. Hope that the administration hasn't made some really malicious BIOS modification, or installed hardware decoding device that stores signals sent to monitor. Don't use passwords, because hardware keyloggers might be installed (that's the easiest place to sniff data), and it's safer to just carry all the data around. For added protection wear some tinfoil around your head.
Re:create password
Posted: Thu Jun 02, 2005 12:21 am
by Solar
mystran wrote:Boot from a CD into your personally "carry-with-me" OS installation, and use a USB memory stick for your home directory. Hope that the administration hasn't made some really malicious BIOS modification, or installed hardware decoding device that stores signals sent to monitor.
Very good advice so far if you're talking
really sensitive data.
Don't use passwords, because hardware keyloggers might be installed (that's the easiest place to sniff data), and it's safer to just carry all the data around.
The problem is, as always, that
real security reduces the number of things you can do. In this setup, you can't retrieve your e-mail, for example.
For added protection wear some tinfoil around your head.
Yes, that's what high-level security ends up as. Tinfoil around your
monitor would be advisable, too, as the displayed contents of a CRT can still be picked up from the other side of the street, given appropriate equipment. (I have
seen this to work, believe me!)
The
only really secure system is one placed in a wire mesh cage to which only you have physical access, with
no cables connected to the outside world. That is, secured against data sniffing.
If you want to be sure about the
integrity of your data, there's much more to pay attention to - randomly chosen, widely used hardware components, widely used Open Source software downloaded from the main mirrors with double-checking on the md5 checksums...
But all this is "military grade" security. Who expects to be "sniffed" by a secret service? For all of
us here, PGP with sensible settings should suffice unless you suspect your admin is
actively and
maliciously trying to sniff your data.
Re:create password
Posted: Thu Jun 02, 2005 2:46 am
by Candy
Solar wrote:
For added protection wear some tinfoil around your head.
Yes, that's what high-level security ends up as. Tinfoil around your
monitor would be advisable, too, as the displayed contents of a CRT can still be picked up from the other side of the street, given appropriate equipment. (I have
seen this to work, believe me!)
The
only really secure system is one placed in a wire mesh cage to which only you have physical access, with
no cables connected to the outside world. That is, secured against data sniffing.
Been watching Enemy of the State again?
Re:create password
Posted: Thu Jun 02, 2005 4:13 am
by Solar
No, I read a lot about computer-related security back when I was interested in PGP and similar security suites - and those papers also listed the "physical" attack methods, too. Then I served my time in the military in a EW unit (electronic warfare)...