Stories
Slash Boxes
Comments
typodupeerror delete not in

+-   Undocumented Backdoor in PGP Whole Disk Encryption-> on Wednesday October 03 2007, @08:49AM A non-mouse Coward

Submitted by A non-mouse Coward on Wednesday October 03 2007, @08:49AM
security
A non-mouse Coward writes "PGP Corporation's widely adopted Whole Disk Encryption product apparently has an encryption bypass feature that allows an encrypted drive to be accessed without the boot-up passphrase challenge dialog, leaving data in a vulnerable state if the drive is stolen when the bypass feature is enabled. The feature is also apparently not in the documentation that ships with the PGP product, nor the publicly available documentation on their website, but only mentioned briefly in the customer knowledge base (PGP customer account required). Jon Callas, CTO and CSO of PGP Corp., responded that this feature was required by unnamed customers and that competing products have similar "dangerous" functionality. There is still no official word from PGP as to why the public documentation withheld recognition of this risky option."
Link to Original Source
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
Everything takes longer, costs more, and is less useful. -- Erwin Tomash