【VeraCrypt】暗号化仮想ドライブ作成ソフト Part20at SOFTWARE【VeraCrypt】暗号化仮想ドライブ作成ソフト Part20 - 暇つぶし2ch■コピペモード□スレを通常表示□オプションモード□このスレッドのURL■項目テキスト100:名無しさん@お腹いっぱい。 15/08/09 01:15:02.78 cLuh2zkM0.net ・システム暗号化使ってなくて一時ファイル経由で鍵がばれたのか ・開発者が米軍でTCにバックドアがあったのか ・監査がFBIとグルで発見されてない脆弱性があるのか 記事からはわからんけどたぶん一番上だよきっとそうだよ 101:名無しさん@お腹いっぱい。 15/08/09 01:33:07.97 BRJTy4cx0.net 実はすでにNSAが脆弱性見つけてるVeraCryptへ移行させるための罠だよ 想像は膨らむね 102:名無しさん@お腹いっぱい。 15/08/09 02:54:23.67 OFzKYUAn0.net TrueCrypt7.1aからの改善点 https://veracrypt.codeplex.com/discussions/569777#PostContent_1313325 Weak Volume Header key derivation algorithm: fixed since the birth of VeraCrypt. As of 2014, any security professional will tell you that PBKDF2 should be used with a minimum of 10000 iteration for a high security, combined with a strong password. The 1000 count comes from 2004 and it is outdated, and that's why the Open Crypto Audit placed it as the first vulnerability. In VeraCrypt, we choose since 2013 a very high iterations count to meet the increasing security requirements, hopefully for the next 10 years. Multiple issues in the bootloader decompressor : fixed in git and it will be released in version 1.0f. This was very challenging because of the size requirements of the bootloader. We had to optimize the code size of many part in order to make room for the modifications of the decompressor. Windows kernel driver uses memset() to clear sensitive data: fixed since version 1.0e TC_IOCTL_GET_SYSTEM_DRIVE_DUMP_CONFIG kernel pointer disclosure: fixed since version 1.0e IOCTL_DISK_VERIFY integer overflow: fixed since version 1.0e MainThreadProc() integer overflow: fixed since version 1.0e MountVolume() device check bypass: fixed since version 1.0e GetWipePassCount() / WipeBuffer() can cause BSOD: fixed since version 1.0e 修正点 correcting memory leaks fixing potential overflow when parsing language file that can exploited. fixing non-absolute DLL/process loads that can be hijacked (Microsoft Security Advisory 2269637). 次ページ最新レス表示レスジャンプ類似スレ一覧スレッドの検索話題のニュースおまかせリストオプションしおりを挟むスレッドに書込スレッドの一覧暇つぶし2ch