Entries Tagged "Schneier news"

Page 45 of 46

Password Safe

Password Safe is a free Windows password-storage utility. These days, anyone who is on the Web regularly needs too many passwords, and it’s impossible to remember them all. I have long advocated writing them all down on a piece of paper and putting it in your wallet.

I designed Password Safe as another solution. It’s a small program that encrypts all of your passwords using one passphrase. The program is easy to use, and isn’t bogged down by lots of unnecessary features. Security through simplicity.

Password Safe 2.11 is now available.

Currently, Password Safe is an open source project at SourceForge, and is run by Rony Shapiro. Thank you to him and to all the other programmers who worked on the project.

Note that my Password Safe is not the same as this, this, this, or this PasswordSafe. (I should have picked a more obscure name for the program.)

It is the same as this, for the PocketPC.

Posted on June 15, 2005 at 1:35 PMView Comments

New Feature: 100 Latest Comments

If you look to the right, under the “Recent Entries,” you’ll see a link to the “100 Latest Comments.” This link takes you to a single page with the 100 most recent comments to this blog, in reverse chronological order.

It’s a quick and easy way to stay abreast of the various conversations going on here at Schneier on Security. I wish other blogs would do this.

Posted on May 18, 2005 at 12:36 PMView Comments

Crypto-Gram

Seven years ago I started writing a monthly newsletter on security. Today, Crypto-Gram has over 120,000 readers, and is still growing.

If you read this blog every day, you don’t need to subscribe to Crypto-Gram. Everything in Crypto-Gram appears first in this blog. But I often update the longer essays, based on new information and reader comments, before including them in Crypto-Gram. The blog is more timely, but Crypto-Gram is more polished.

Some of you might prefer to read my writing in a monthly digest rather than in bits and pieces. Some of you might prefer an email that comes to you, rather than having to remember to check this blog. If so, try Crypto-Gram.

Crypto-Gram comes out on the 15th of every month. You can read the current issue (it came out today) here. You can read back issues here.

And if you want to subscribe to the monthly email—I promise no marketing e-mail ever—here.

Posted on May 15, 2005 at 3:01 PMView Comments

Blowfish on "24"

Two nights ago, my encryption algorithm Blowfish was mentioned on the Fox show “24.” An alleged computer expert from the fictional anti-terror agency CTU was trying to retrieve some files from a terrorist’s laptop. This is the exchange between the agent and the terrorist’s girlfriend:

They used Blowfish algorithm.

How can you tell?

By the tab on the file headers.

Can you decrypt it?

CTU has a proprietary algorithm. It shouldn’t take that long. We’ll start by trying to hack the password. Let’s start with the basics. Write down nicknames, birthdays, pets—anything you think he might have used.

Posted on April 27, 2005 at 12:26 PMView Comments

Regulation, Liability, and Computer Security

For a couple of years I have been arguing that liability is a way to solve the economic problems underlying our computer security problems. At the RSA conference this year, I was on a panel on that very topic.

This essay argues that regulation, not liability, is the correct way to solve the underlying economic problems, using the analogy of high-pressure steam engines in the 1800s.

Definitely worth thinking about some more.

Posted on February 25, 2005 at 8:00 AMView Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.