[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Allow encfs into jessie?



Quoting Eduard Bloch (edi@gmx.de):

> Template: encfs/security-information
> Type: note
> _Description: Encfs Security Information

Besides using an Evil Debconf Note (;-) ), is there a reason for
capitalizing every noun in the note title ?

BTW, that might be a use case for the debconf "error" datatype which
will emphasize the note even more on some frontends.

>  According to a security audit by Taylor Hornby (Defuse Security), the current
>  implementation of Encfs is vulnerable or potentially vulnerable to multiple
>  attacks on the encrypted data. This especially affects use cases where the
>  attacker has read/write access to the encrypted directory or has enough
>  knowledge of the unencrypted file system contents.
>  .
>  In the current situation encfs should not be considered a safe home for
>  sensible data. This package should be only used to retrieve information from
>  previously encrypted sources, and even this action contains some risk of
>  receiving compromised data.

A call for translation would be appreciated too, of course.


Attachment: signature.asc
Description: Digital signature


Reply to: