You can subscribe to this list here.
| 2000 |
Jan
|
Feb
(9) |
Mar
(4) |
Apr
(5) |
May
(27) |
Jun
(3) |
Jul
(5) |
Aug
(3) |
Sep
(25) |
Oct
(21) |
Nov
(2) |
Dec
(2) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2001 |
Jan
(3) |
Feb
|
Mar
(3) |
Apr
(9) |
May
(2) |
Jun
(20) |
Jul
(9) |
Aug
(2) |
Sep
(5) |
Oct
|
Nov
(8) |
Dec
(3) |
| 2002 |
Jan
(3) |
Feb
(6) |
Mar
(13) |
Apr
(20) |
May
(10) |
Jun
(6) |
Jul
(2) |
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2003 |
Jan
(10) |
Feb
|
Mar
(2) |
Apr
|
May
(2) |
Jun
(1) |
Jul
(3) |
Aug
(1) |
Sep
|
Oct
(12) |
Nov
(1) |
Dec
(5) |
| 2004 |
Jan
(3) |
Feb
(3) |
Mar
|
Apr
(6) |
May
(4) |
Jun
|
Jul
|
Aug
(1) |
Sep
|
Oct
|
Nov
(1) |
Dec
(1) |
| 2005 |
Jan
(9) |
Feb
(8) |
Mar
(12) |
Apr
(8) |
May
|
Jun
(6) |
Jul
|
Aug
(1) |
Sep
(1) |
Oct
|
Nov
|
Dec
(3) |
| 2006 |
Jan
(3) |
Feb
(3) |
Mar
(3) |
Apr
|
May
(2) |
Jun
|
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2007 |
Jan
|
Feb
|
Mar
(4) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(3) |
Oct
(1) |
Nov
(2) |
Dec
|
| 2008 |
Jan
|
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
(2) |
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2009 |
Jan
|
Feb
(9) |
Mar
|
Apr
(3) |
May
|
Jun
|
Jul
|
Aug
(1) |
Sep
(1) |
Oct
|
Nov
|
Dec
|
| 2010 |
Jan
|
Feb
(2) |
Mar
(2) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(3) |
Oct
|
Nov
|
Dec
|
| 2011 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(1) |
Oct
(2) |
Nov
|
Dec
|
| 2013 |
Jan
|
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(4) |
Oct
|
Nov
|
Dec
|
|
From: Genie M. <Mo...@ga...> - 2005-04-12 13:56:36
|
Hello, Cahusac would certainly have adopted that course if only his men idiotically, all teeth and eyeballs. those names. He would cast out the maudlin ideals by which he ha died in his bonds before ever you reached the Encarnacion. Your uncle, the Colonel, is of a different opinion, said he, wh the collar of his doublet, and lugged him out into the open. As he stood there, above the ghastly shambles in the waist of the fool's absence. Cartagena agreed, having no choice in the matter, and on the next Have a nice day. |
|
From: Eddie M. <li...@he...> - 2005-04-07 15:33:26
|
Ack, well, I may have to leave it for 1.x version of keyring. I'm using the 4.0.3 release of the CDK since my palm (Zire 71) doesn't support the new hotsync manager releases. In it, there is a SyncCallApplication call but it's deprecated. There is a SyncCallRemoteModule call, but it doesn't let you specify the launch code. thanks, Eddie |
|
From: Jochen H. <hoe...@gm...> - 2005-04-07 13:49:47
|
Hello Eddie, On Apr 6, 2005 5:44 PM, Eddie McCreary <li...@he...> wrote: > I'm finally at the boring but important part of fixing bugs and > writing docs, however I'll be out of town fri-mon so it will probably > be one more week before I can release something. > > One issue I could use help on, the keys are cached on the PDA in I > believe a db called Keys-Gtkr-Temp. That was before 1.1. The problem was that the database with the key (the snib) was actually copied to the PC. Now the snib is held in some more secure place. > If I change the master password on > the desktop and sync, I will get an exception because on the palm the > program is still using the cached password. If I set my timeout > preference to zero this isn't an issue. Yes, this is a known problem. I think it isn't too serious, because 1. there is only a warning that data cannot be encrypted and garbage is displayed. As soon as one locks the database and unlocks again everything is fine. 2. The problem only occurs if the database was unlocked when a new database with a new password is synced. With the new format in keyring-2.0 the problem won't occur any more. > Any ideas on how to for the software on the PDA to reset it's cache? I'm not sure what you can do from the conduit site. Starting keyring with sysAppLaunchCmdAlarmTriggered or sysAppLaunchCmdTimeChange should eradicate the snib immediately. Regards, Jochen -- Jochen Hoenicke, University of Oldenburg, 26111 Oldenburg, Germany Email: hoe...@in... Tel: +49 441 798 3124 |
|
From: Eddie M. <li...@he...> - 2005-04-06 15:44:36
|
I'm finally at the boring but important part of fixing bugs and writing docs, however I'll be out of town fri-mon so it will probably be one more week before I can release something. One issue I could use help on, the keys are cached on the PDA in I believe a db called Keys-Gtkr-Temp. If I change the master password on the desktop and sync, I will get an exception because on the palm the program is still using the cached password. If I set my timeout preference to zero this isn't an issue. Any ideas on how to for the software on the PDA to reset it's cache? I've tried to delete the Keys-Gtkr-Temp db during sync, but I'm getting a db not found error message. thanks. Eddie |
|
From: zxx_v008 <zxx...@ns...> - 2005-04-02 00:23:12
|
ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª ©ÂÄ̦ñ¶å¢ãªlÈÉÈÁÄàâßçêÈ¢àÌ «««««««««««««««««««@ @ @@@@@@@@@@@@@@@@@@@@@ http://www.angelfire.com/ks3/manimani7day @ ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª lÈcnîEEE^cnŧ©ÉJ©êÄ¢éBBB ««««««««««««««««««« http://www.angelfire.com/ks3/manimani7day http://www.angelfire.com/ks3/manimani7day ªªªªªªªªªªªªªªªªªªª ^Z[XfB[BlÈp[àyôB»Ìé§ÆÍ ss`à¢È Ƚͱ±ÉÔðêI ßµ¢±Æ¾ª¨Êê¾B pau...@ya... ******************************************************************** VbsOgð»à»!f¢ÀSÎ http://www.cash-rc.com/ |
|
From: Eddie M. <la...@he...> - 2005-03-31 18:16:43
|
Jochen Hoenicke wrote: > I would say, finish the one for version 1.2.3 first and then start supporting > the new format. Does the xml file store the data in encrypted form? As I > understand it the hotsync is noninteractive so you can't decrypt the data, > right? > > You should have a version flag in XML file to distinguish new and old format > so you can support both. Yes, it stores it as a base64 encoded version of encrypted portion of the record. While technically it's possible to add dialogs during the sync process, it's not recommended as with network sync the user may be not access to the machine the hotsync process is running on. And besides, I wouldn't want to save the data unencrypted anyway. The only thing I'm need to figure out now is category syncing, the palm docs are bit unclear on it. Record syncing is working great. Then I need to finish my cmd line app that updates the xml file to support all the necessary functions; add/remove/edit categories, add/remove/edit records, change password, etc. Most of the code is there, it's just coming up with a consistent option set and error checking. I need to make an error checking/logging pass over the conduit too, so I should have a version stable enough for testing next week. thanks, Eddie -- Eddie McCreary Outside of a dog, a book is a man's best mailto:la...@he... friend. Inside of a dog, it's too dark http://www.heorot.org to read. -Groucho Marx |
|
From: Jochen H. <Hoe...@In...> - 2005-03-31 09:42:19
|
On Tuesday 29 March 2005 00:34, Eddie McCreary wrote: > I've put together a mirror sync conduit for windows that seems to work=20 > with Hotsync Manager 4.1 and keyring 1.2.3. However, before I finished=20 > cleaning up the code I noticed there is pre-release version of keyring=20 > 2.0 coming out that has a new database format. >=20 > Is it worth finish this up or should I start rewriting it to use the new= =20 > database format for 2.0? I would say, finish the one for version 1.2.3 first and then start supporti= ng the new format. Does the xml file store the data in encrypted form? As I understand it the hotsync is noninteractive so you can't decrypt the data, right? You should have a version flag in XML file to distinguish new and old format so you can support both. =2D-=20 Jochen Hoenicke, University of Oldenburg, 26111 Oldenburg, Germany Email: hoe...@in... Tel: +49 441 798 3124 |
|
From: Eddie M. <li...@he...> - 2005-03-28 22:34:46
|
I've put together a mirror sync conduit for windows that seems to work with Hotsync Manager 4.1 and keyring 1.2.3. However, before I finished cleaning up the code I noticed there is pre-release version of keyring 2.0 coming out that has a new database format. Is it worth finish this up or should I start rewriting it to use the new database format for 2.0? Currently it performs a mirror sync with an xml file, this should make it easy to write clients for it. I'm starting a java client now to test the conduit better, to this point I've only tested modified the non encrypted portions of the data. thanks, Eddie -- Eddie McCreary Outside of a dog, a book is a man's best mailto:li...@he... friend. Inside of a dog, it's too dark http://www.heorot.org to read. -Groucho Marx |
|
From: Jochen H. <hoe...@gm...> - 2005-03-16 12:06:37
|
Hello Does anyone has experiences with hot syncing under palm os 5.0/windows XP or experienced something similar as in the forwarded message? Jochen ---------- Forwarded message ---------- From: SourceForge.net <no...@so...> Date: Fri, 11 Mar 2005 01:12:52 -0800 Subject: [ gnukeyring-Bugs-1161200 ] HotSyncing of the Keys-Gtkr.pdb file doesn't work To: no...@so... Bugs item #1161200, was opened at 2005-03-11 01:12 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=100306&aid=1161200&group_id=306 Category: application Group: bug Status: Open Resolution: None Priority: 5 Submitted By: dborkov (dborkov) Assigned to: Nobody/Anonymous (nobody) Summary: HotSyncing of the Keys-Gtkr.pdb file doesn't work Initial Comment: Hi, I am using sony CLIE and palm os 5.0 with keyring 2.0 pre 4 (feb 26). The desktop is Windows xp. I created a new database and hot synced it. The backup file was created fine. Then I modified my database by adding new entries and hot synced it after each modification. First two or three time the backup file was updated successfully after each database modification. But, starting after the second or third time, hot sync repeatedly failed to update the backup file in spite of the database modifications. I tried the same exercise several times from scratch by removing the *pdb file from handheld's memory, and observed the same behavior each time. The only difference might have been the number of initial successful backup file updates. The keyring conduit in HotSync is on. Thanks, Drazen ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=100306&aid=1161200&group_id=306 -- Jochen Hoenicke, University of Oldenburg, 26111 Oldenburg, Germany Email: hoe...@in... Tel: +49 441 798 3124 |
|
From: sada <zc...@ms...> - 2005-03-12 06:05:19
|
```````````````````` ```````````````````` K^ÆÍIH¨à¾Á½èId¾Á½èIö¤¾Á½èI ©ªÌ~µÄ¢éàÌ»êªèÉüÁ½Æ«ÍK^Å·æËI ÅÍó¶ÌÄ©½âp`RÌשèûAnÌÄûª Á½çǤŵ天H http://free-contents.com/senkin/ ³¿ÅK^ðE¦éû@𳦿á¢Ü·B ³¿Æ¾ÁÄཾPÈû@ÈñÅ·æIH http://free-contents.com/senkin/ ```````````````````` ```````````````````` zMÛÌûͱ¿ç alm...@ya... |
|
From: sadabncv <z_...@ma...> - 2005-03-05 12:22:10
|
âÁÄàÝÈ¢¤¿©çA w_¾ÁÄx߯Ģܹñ©H ÊÍs®µÈ¢ÆÏíèܹñæËB ܸAs®ð¨±µÄÝܵå¤I http://fresh-lime.net/ps/to-roku/ l¶Ì]@ÍAÓOÈÆ±ëÉ èÜ·B ȽÌK 鱯ðFÁÄ BEBEBEBEBEEB http://fresh-lime.net/ps/to-roku/ zMâ~ó]ÌÌûͱ¿çÜÅB sim...@ya... |
|
From: fa <sf...@dx...> - 2005-03-04 20:07:57
|
Fl©ç¨ñ¹¢½¾¢½A oï¢Ì̱kWô l»ê¼êÌo ÁÄA ÇñŢ龯ÅA\ʢŷ` »¡ª éûAÇñÅÝľ³¢I http://centertown.be/ps/taiken/ zMâ~ͱ¿ç ¦@pau...@ya... |
|
From: Jochen H. <hoe...@gm...> - 2005-03-04 19:22:09
|
On Fri, 4 Mar 2005 18:34:17 +0000, Chris Green <ch...@ar...> wrote: > I have a need to extract data from the keyring database on the command > line so I've taken the existing keyring-link utility and have done a > few simple/trivial changes to make it more useful for my use at > least. If anyone is interested I'm quite happy to upload this > version. Did you work on the latest version (keyring-link-2.0-pre1 or the latest cvs release)? The only change from 0.1.1 is that this version supports keyring-2.0pre (database version 5). You can either post the patch to the sourceforge patch tracker, or post it here. Preferrably as a diff against the latest release/cvs version (they should be identical). > The changes are basically as follows:- > > Remove the password from the command line arguments leaving only > the keyring database file name. > > The file name defaults to $HOME/.jpilot/Keys-Gtkr.pdb so you don't > have to enter it normally. Of course this depends on using jpilot. Maybe this could be configurable by environment variable. > When keyring-link is run (I've actually renamed it to kl) it > prompts 'Key: ' and expects the user to enter an entry name > followed by a password in the format '<entry>/<password>', if the > password is correct then just the <entry> is output. If you read the password from tty, it may be better to use getpass() for getting the password (which hides the entered password), at least if on a tty. It might make it less portable though. > I've changed the output format a little to suit my needs and have > removed the use of the 'rs_xxx' functions for error output, it just > outputs to stderr. > -- Jochen Hoenicke, University of Oldenburg, 26111 Oldenburg, Germany Email: hoe...@in... Tel: +49 441 798 3124 |
|
From: Chris G. <ch...@ar...> - 2005-03-04 18:34:29
|
I have a need to extract data from the keyring database on the command
line so I've taken the existing keyring-link utility and have done a
few simple/trivial changes to make it more useful for my use at
least. If anyone is interested I'm quite happy to upload this
version.
The changes are basically as follows:-
Remove the password from the command line arguments leaving only
the keyring database file name.
The file name defaults to $HOME/.jpilot/Keys-Gtkr.pdb so you don't
have to enter it normally.
When keyring-link is run (I've actually renamed it to kl) it
prompts 'Key: ' and expects the user to enter an entry name
followed by a password in the format '<entry>/<password>', if the
password is correct then just the <entry> is output.
If you enter '/<password>' the whole database is output.
I've changed the output format a little to suit my needs and have
removed the use of the 'rs_xxx' functions for error output, it just
outputs to stderr.
--
Chris Green (ch...@ar...)
"Never ascribe to malice that which can be explained by incompetence."
|
|
From: Chris G. <ch...@ar...> - 2005-03-04 18:26:37
|
On Fri, Mar 04, 2005 at 06:56:52PM +0100, Jochen Hoenicke wrote:
>
> Lastly not storing the MD5 checksum would not prevent brute force
> attacks that make use of known plaintext. If you could get my database
> you could try to decrypt the "Sourceforge" record with each password
> until it decrypts to "hoenicke" in the account field.
>
But in the general case this method of attack won't be available,
you'd have to know something about the user and/or file to do this.
OK about the other points though, I'd sort of forgotten that keyring
is a two-way utility. I'd been playing with keyring-link to make a
more acceptable command line tool for extracting information from the
keyring database. I've posted another message about that.
--
Chris Green (ch...@ar...)
"Never ascribe to malice that which can be explained by incompetence."
|
|
From: Jochen H. <hoe...@gm...> - 2005-03-04 17:57:03
|
On Fri, 4 Mar 2005 15:56:58 +0000, Chris Green <ch...@ar...> wrote: > This is probaly a naive question but anyway here goes. > > Why does gnu-keyring store the password? OK, it's encrypted, but it > does open up the possibility of 'brute force' attacks because the > attacker can immediately see when the right password is tried, the MD5 > encrypted passwords will match. > > Surely, since we don't have any need to validate the password itself > (as one would for a login for example), the password can simply be > used to decrypt the data and the data is then returned. The result > will be rubbish unless the correct password is provided. This > prevents brute force attacks because the attacker won't know when the > right password is tried - unless he knows what the data is already. One problem is that the regular user may not notice that he mistyped the password. E.g. if he enters a new record he won't get any hint that the password was wrong. Also he may accidently corrupt records by editing them with the wrong password. And if he changes the password and mistyped the old password there, he is completely lost. The password is also used to prevent some operations such as changing the password, deleting records, editing categories. Of course an attacker can also delete the database via the launcher, but he cannot corrupt the database only partly (except by HotSync), so that it won't be noticed immediately. Lastly not storing the MD5 checksum would not prevent brute force attacks that make use of known plaintext. If you could get my database you could try to decrypt the "Sourceforge" record with each password until it decrypts to "hoenicke" in the account field. Regards, Jochen -- Jochen Hoenicke, University of Oldenburg, 26111 Oldenburg, Germany Email: hoe...@in... Tel: +49 441 798 3124 |
|
From: Chris G. <ch...@ar...> - 2005-03-04 15:57:12
|
This is probaly a naive question but anyway here goes.
Why does gnu-keyring store the password? OK, it's encrypted, but it
does open up the possibility of 'brute force' attacks because the
attacker can immediately see when the right password is tried, the MD5
encrypted passwords will match.
Surely, since we don't have any need to validate the password itself
(as one would for a login for example), the password can simply be
used to decrypt the data and the data is then returned. The result
will be rubbish unless the correct password is provided. This
prevents brute force attacks because the attacker won't know when the
right password is tried - unless he knows what the data is already.
--
Chris Green (ch...@ar...)
"Never ascribe to malice that which can be explained by incompetence."
|
|
From: Jochen H. <Hoe...@In...> - 2005-02-26 12:15:53
|
A new test release of Keyring is out: Keyring for PalmOS 2.0-pre4 Copyright 1999-2002 by Martin Pool Copyright 2001-2005 by Jochen Hoenicke http://gnukeyring.sourceforge.net/prerelease.html Changes since pre3: * Fixed memory leaks in upgrade and reencrypt procedure * Added 5-way navigation support (although untested as I don't have an new palm and the Treo600 simulator does not run for me). This is a prerelease of keyring and it may contain bugs that destroy the database or even require a hard reset. So MAKE A BACKUP before installing this. And keep a backup of the Keys-Gtkr.pdb file in a separate place in case you need to downgrade to 1.2.2 later. If you have used keyring-2.0-pre1 you should remove Keyring-Test now. This will also remove the test database. This second test release does not use it's own test database but upgrades the database of keyring-1.x If you have used keyring-1.x before, the new version will first ask you to upgrade the database. There is no way to downgrade again except by recovering from an old backup. The upgrade process will ask you to set the password again and to choose an encryption cipher and an iteration count. You have to enter the old password from keyring-1.x. A big value for the iteration count "Iter:" makes password checking slow. This is to prevent brute-force attacks. Unfortunately a Palm is very slow in comparison to a desktop PC, so checking a single password takes=20 more than a second for 1000 iterations. I recommend the value 500 as=20 compromise between speed and security. Three encryption ciphers are supported: 3-DES (with 168 bit key),=20 AES (with 128 bit key) and AES-256 (with 256 bit keys). If you plan to use AES you have to install the library of course. If you choose "No" as Cipher you do not get any encryption. This option is there for testing purposes only, it will be removed in the final release. You only need MDlib for upgrading from an old database (in that case you should already have installed it). After upgrading you can remove this library. If you use AES, you can also remove DESlib after upgrading. The database format has not changed since pre1, so there is no need for a new keyring-link release. Jochen |
|
From: Benjamin E. <bd...@gm...> - 2005-02-13 17:59:08
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Feb 13, 2005, at 11:09 AM, Jochen Hoenicke wrote: > You're right, the database is Keys-Gtkr. However, I am not sure how > the SD > card mechanism works (I still have an old Palm without any SD card > slot). > Keyring is expecting the database in main RAM, so you probably need to > copy > it there (except if the card manager does that automatically). This is correct-- before running a program, it must be copied (or moved) from the SD card to internal memory. Most launcher programs do this automatically, but if yours doesn't, copy Keys-Gtkr.pdb, Keyring.prc, and the library files to the internal memory before trying to run Keyring. Personally, I find Keyring important and useful enough that it always stays in internal memory :-) HTH, - -- Benjamin D. Esham bd...@gm... | http://bdesham.net | AIM: bdesham128 Wikipedia, the Free Encyclopedia --- http://en.wikipedia.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (Darwin) iD4DBQFCD5VVzOC3TdZ2u5oRAmHQAJittD/jSdVd4wpkGYeF16E0cHNhAJ9tG/kx G3D23hnFbwDzMEXpiYy+kw== =cJ6e -----END PGP SIGNATURE----- |
|
From: Jochen H. <Hoe...@In...> - 2005-02-13 16:10:04
|
Hello hzhu, > Thank you very much for the great product. I have been using it for last 2 > years. It's great. I recently upgrade to Treo 600 and Keyring-1.2.3-en As > my keyring's getting bigger, I am thinking of moving it to SD card to free > up some RAM. but after I copied the keyring from RAM to the SD card and > delete the original copy in RAM, I lost the keyring database, the keyring > in my SD card couldn't locate the keyring data. I tried to work it around > by copying the backup keyring files: keyring, xxxlib and Keys-Gtkr from my > desktop to SD card, but the data was still nowhere to find. Could you > kindly educate me on what's the name of keyring database(I thought it was > Keys-Gtkr)? How can I move my keyring to my SD card. You're right, the database is Keys-Gtkr. However, I am not sure how the SD= =20 card mechanism works (I still have an old Palm without any SD card slot). = =20 Keyring is expecting the database in main RAM, so you probably need to copy it there (except if the card manager does that automatically). I think the DES/MDLib libraries also need to reside in main memory, due to= =20 the way GLib shared libraries work.=20 Maybe someone on the keyring mailing list has some experience with running keyring from SD card. I have CCed the mailing list. Regards, Jochen =2D-=20 Jochen Hoenicke, Universit=E4t Oldenburg, D-26111 Oldenburg Mail: hoe...@in... Tel: +49 441 798 3124 |
|
From: Jochen H. <Hoe...@In...> - 2005-02-09 12:17:30
|
I wrote: > I just noticed a bug. When changing the master password all records are > put into the "Unfiled" category. I hope to have a fix for this soon... The bug is fixed, keyring-2.0-pre3 is now available at the prerelease=20 page. http://gnukeyring.sourceforge.net/prerelease.html If you were hit by this bug, you can reinstall Keys-Gtkr.pdb from your backup, or update the categories of all entries manually. Jochen =2D-=20 Jochen Hoenicke, University of Oldenburg, 26111 Oldenburg, Germany Email: hoe...@in... Tel: +49 441 798 3124 |
|
From: Jochen H. <Hoe...@In...> - 2005-02-08 23:16:59
|
I wrote: > A new test release of Keyring is out: > Keyring for PalmOS 2.0-pre2 Warning: =20 I just noticed a bug. When changing the master password all records are put into the "Unfiled" category. I hope to have a fix for this soon... Jochen =2D-=20 Jochen Hoenicke, Universit=E4t Oldenburg, D-26111 Oldenburg Mail: hoe...@in... Tel: +49 441 798 3124 |
|
From: Stuart, B. <St...@te...> - 2005-02-08 16:21:20
|
> -----Original Message----- > From: gnu...@li... > [mailto:gnu...@li...]On Behalf Of > Jochen Hoenicke > > A new test release of Keyring is out: > Keyring for PalmOS 2.0-pre2 Great news! I'd be lost (and locked-out of many applications) without Keyring. Are you accepting donations? Thanks! - Bill Baltimore, MD, USA |
|
From: Jochen H. <Hoe...@In...> - 2005-02-08 15:59:05
|
A new test release of Keyring is out: Keyring for PalmOS 2.0-pre2 Copyright 1999-2002 by Martin Pool Copyright 2001-2005 by Jochen Hoenicke http://gnukeyring.sourceforge.net/prerelease.html This is a prerelease of keyring and it may contain bugs that destroy the database or even require a hard reset. So MAKE A BACKUP before installing this. And keep a backup of the Keys-Gtkr.pdb file in a separate place in case you need to downgrade to 1.2.2 later. If you have used keyring-2.0-pre1 you should remove Keyring-Test now. This will also remove the test database. This second test release does not use it's own test database but upgrades the database of keyring-1.x If you have used keyring-1.x before, the new version will first ask you to upgrade the database. There is no way to downgrade again except by recovering from an old backup. The upgrade process will ask you to set the password again and to choose an encryption cipher and an iteration count. You have to enter the old password from keyring-1.x. A big value for the iteration count "Iter:" makes password checking slow. This is to prevent brute-force attacks. Unfortunately a Palm is very slow in comparison to a desktop PC, so checking a single password takes=20 more than a second for 1000 iterations. I recommend the value 500 as=20 compromise between speed and security. Three encryption ciphers are supported: 3-DES (with 168 bit key),=20 AES (with 128 bit key) and AES-256 (with 256 bit keys). If you plan to use AES you have to install the library of course. If you choose "No" as Cipher you do not get any encryption. This option is there for testing purposes only, it will be removed in the final release. You only need MDlib for upgrading from an old database (in that case you should already have installed it). After upgrading you can remove this library. If you use AES, you can also remove DESlib after upgrading. The database format has not changed since pre1, so there is no need for a new keyring-link release. =46uture Plans: The biggest hurdle in releasing 2.0 is solved, as there=20 is now an upgrade path from 1.x. There are a few small pending patches, e.g. the patch to use the 4-way navigator. Also the translations have to be updated. The 2.0 release will not have major new features, though. Jochen =2D-=20 Jochen Hoenicke, University of Oldenburg, 26111 Oldenburg, Germany Email: hoe...@in... Tel: +49 441 798 3124 |
|
From: Benjamin E. <bd...@gm...> - 2005-01-26 04:34:06
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Jan 25, 2005, at 11:21 PM, Eugene Y. Vasserman wrote:
> I'd rather have 2.0 and upgrade the database myself than have nothing!
> :)
What new features will be in 2.0? Or is it just a code rewrite? It'd
really be a
shame if development on Keyring stopped.
- --
Benjamin D. Esham { http://bdesham.net
bd...@gm... } AIM: bdesham 1 2 8
Six Gmail invites -- e-mail me if you're interested.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (Darwin)
iD8DBQFB9x2pzOC3TdZ2u5oRAkdzAJ9QigcIFkXAAj6OqNByGR5ANhMwDQCgnfe9
qH3lMy5jcoHCVFaMi8kf1fE=
=vEOl
-----END PGP SIGNATURE-----
|