Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Media Gone Mad
Tim Mullen, 2003-02-24

Why last week's big Windows security hole is nothing more than technology press hot air.

Comments Mode:
Media Gone Mad 2003-02-24
Anonymous (1 replies)
Media Gone Mad 2003-02-27
Linux_Hawk
I agree completely. 2003-02-24
Anonymous (4 replies)
I agree completely. 2003-02-24
Anonymous
Re: I agree completely. 2003-02-25
Anonymous (2 replies)
Re: I agree completely. 2003-02-25
Anonymous (1 replies)
Re: Re: I agree completely. 2003-02-26
Anonymous
Re: I agree completely. 2003-02-25
Anonymous (2 replies)
Re: I agree completely, or NOT 2003-02-26
Anonymous (2 replies)
Re: I agree completely, or NOT 2003-02-27
Anonymous
Re: I agree completely, or NOT 2003-02-27
Eric Grabowski (eric@mazenet.com) (1 replies)
Re: I agree completely, or NOT 2003-02-27
Anonymous
Re: I agree completely. 2003-02-26
Seb (1 replies)
Re: I agree completely. - thank you 2003-02-28
Anonymous (1 replies)
I agree completely. 2003-02-26
Anonymous
Media Gone Mad 2003-02-24
Anonymous (1 replies)
Media Gone Mad 2003-02-24
Anonymous (1 replies)
Media Gone Mad 2003-02-26
Anonymous
For once I agree with you. 2003-02-24
Anonymous
at least someone sees sense 2003-02-24
ravidew (1 replies)
Media Gone Mad 2003-02-24
Anonymous
Bravo! 2003-02-24
Keydet89@yahoo.com
Media Gone Mad or not? 2003-02-24
Anonymous
Norteamericano Gone Mad 2003-02-25
John Comeau http://risp.org/members/jcomeau (1 replies)
Norteamericano Gone Mad 2003-02-25
Gavin
Media Gone Mad 2003-02-25
Anonymous (4 replies)
Media Gone Mad 2003-02-25
Anonymous (1 replies)
Media Gone Mad 2003-02-26
Anonymous (1 replies)
Media Gone Mad 2003-02-27
Anonymous (1 replies)
Media Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-26
Anonymous
Wrong on at least one count 2003-02-26
Anonymous
Media Gone Mad 2003-02-26
Anonymous
Media Gone Mad 2003-02-25
Anonymous
WRONG! 2003-02-26
Charles Hill (9 replies)
Actually, it is CRITICAL in one aspect.

If Avaya's security consultant Ken Pfeil is correct when he said:

"If the system is a member of a workgroup and not a domain, you can just change the user's password that the file was encrypted under," Pfeil said. "Then you can log on as that user having access to the encrypted file."

Then EFS is useless in the standard configuration for protecting hard drives. Specifically, hard drives on LAPTOPS, which frequently get stolen.

Most likely this is an IMPLEMENTATION issue, though, and NOT a "hole" in XP. It sounds like the certificate/key used for EFS is stored on the drive, and the password for it is tied to the Workgroup/Domain password. The certificate/key really needs to be stored on a USB key or other removable media, so it can be kept separate from the system.

Encrypting files/folders/partitions on hard drives is supposed to guard against exposure EVEN WHEN CONTROL OF THE SYSTEM IS COMPROMISED!

Case in point -- laptops. What is the point encrypting data on the drives if when stolen, the machine can be consoled and the password changed, opening all the files?

I do not know if you can move the certificate/key off to removable media. If you can, like I suspect, then it is an implementation issue and not a "hole". If not...

You are right in that it was overplayed as a major catastrophy, though. For almost all other cases, if you've lost control of the hardware, you're screwed.

-Charles Hill

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/144/18349#18349
WRONG! 2003-02-26
Anonymous
WRONG! 2003-02-26
Anonymous
THANK YOU! 2003-02-26
Anonymous
WRONG!....err...not 2003-02-26
Anonymous
WRONG! 2003-02-26
Ralf (1 replies)
WRONG! 2003-02-27
Anonymous
re: WRONG! 2003-02-26
Anonymous
WRONG! 2003-02-26
jonsteph (1 replies)
WRONG! 2003-02-27
Anonymous
WRONG! 2003-02-27
Anonymous
WRONG! 2003-02-28
Anonymous
Media Gone Mad 2003-02-26
Jimmy
Media Gone Mad 2003-02-26
Anonymous
Linux "boot" floppy? Wow, I'm impressed. 2003-02-26
TJ Miller jr (23 replies)
Linux "boot" floppy? Wow, I'm impressed. 2003-02-26
Anonymous (1 replies)
Actually, fellow, there -is- one. 2003-02-26
Anonymous
Linux "boot" floppy? Wow, I'm impressed. 2003-02-26
Daniel Franklin
Linux "boot" floppy? Wow, I'm impressed. 2003-02-26
Anonymous (2 replies)
Columnist Gone Mad 2003-02-26
Anonymous (2 replies)
Columnist Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-26
Anonymous
My Experience with The Linux 2003-02-26
Egg Troll (14 replies)
re: My Experience with The Linux 2003-02-26
Stonewolf
My Experience with The Linux 2003-02-26
Anonymous
My Experience with The Linux 2003-02-26
Anonymous
My Experience with The Linux 2003-02-27
Anonymous
Feed the troll 2003-02-27
Anonymous
Re: My Experience with The Linux 2003-02-27
Anonymous
My Experience with The Linux 2003-02-27
Anonymous
Re: My Experience with The Linux 2003-02-27
Anonymous
My Experience with The Linux 2003-02-27
Anonymous (1 replies)
Re: My Experience with The Linux 2003-02-27
Anonymous
My Experience with The Linux 2003-02-27
Anonymous
My Experience with The Linux 2003-02-27
Anonymous (1 replies)
My Experience with The Linux 2003-02-27
Anonymous (1 replies)
Egg Troll Rules! Anonymous Doesn't. 2003-02-28
Anonymous (1 replies)
As if 2003-03-03
Anonymous
My Experience with The Linux 2003-03-05
blacklight
Linux Boot Floppy 2003-02-26
Anonymous
Joy! 2003-02-26
Anonymous
Media Gone Mad 2003-02-26
Anonymous
Media Gone Mad 2003-02-26
Anonymous
Media Gone Mad 2003-02-26
Anonymous (1 replies)
Media Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-26
Anonymous
You don't need a Linux boot floppy 2003-02-27
Aaron Brooks
Media Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-27
icewhit
Media Gone Mad 2003-02-27
Anonymous (1 replies)
Media Gone Mad 2003-02-27
Roberto J Dohnert
Defined media 2003-02-27
bri guy
Media Gone Mad 2003-02-27
Anonymous
Media Gone Mad 2003-02-27
Cent
Alert: Major Security Flaws 2003-02-27
Asmo (2 replies)
Alert: Major Security Flaws 2003-02-27
Anonymous
Alert: Major Security Flaws 2003-02-28
Anonymous
This IS a major vulnerability 2003-02-27
obadii@hushmail.com (2 replies)
This IS a major vulnerability 2003-03-02
Anonymous
Media Gone Mad - bye bye *nix 2003-02-27
Anonymous (1 replies)
Media Gone Mad - bye bye *nix 2003-03-02
Anonymous
Media Gone Mad 2003-02-28
Anonymous
Media Gone Mad 2003-02-28
Anonymous
Media Gone Mad 2003-03-02
Anonymous
Media Gone Mad 2003-03-03
Anonymous
STOOPID PEOPLE 2003-03-03
GENIUS GUY (2 replies)
STOOPID PEOPLE 2003-03-04
Anonymous
STOOPID PEOPLE - uhm, yeah. 2003-03-04
Anonymous
It is unfortunate... 2003-03-03
Glenn Schulz (1 replies)
It is unfortunate...that you don't understand 2003-03-04
Anonymous (1 replies)
It is unfortunate...that Glenn learned security from a text book. 2003-03-05
Erik (1 replies)
Reality 2003-03-06
Glenn Schulz (1 replies)
Agreement 2003-03-06
Erik (2 replies)
It has been a pleasure 2003-03-07
Glenn Schulz
Agreement 2003-03-07
FUNNY (2 replies)
MICROSOFT SUCKS! 2003-03-04
[ Discussion Closed ] (1 replies)
MICROSOFT SUCKS! - your a dink. 2003-03-06
Anonymous
Media Gone Mad - Strikeback 2003-03-05
Anonymous
Media Gone Mad - Linux sucks 2003-03-06
Anonymous
what more can I do 2003-03-06
Tigger







 

Privacy Statement
Copyright 2009, SecurityFocus