in reply to Re: Is data in RAM insecure, or am I just paranoid?
in thread Is data in RAM insecure, or am I just paranoid?
Actually, I did say a bit about the network. Its a windows network, (windows 2003 server, I believe) with the exception of the database servers which are on Linux.
How is it vulnerable after the data is unencrypted? As I stated, the encrypted data is downloaded to a desktop application over SSL and THEN unencrypted via the private key on the desktop users system. (a location not where the servers are).
The data is fairly secure on the way from a users browser to the webserver (via SSL) and even if some program like Ettercap can capture encrypted data .. well, its encrypted.
My biggest worry is the unencrypted data, at the webserver, before I've run it through GNUPG (public/private key encryption at 2048 bits).
So ... how do I protect the pre-encrypted data in memory? or is there no way an ourside program can access data in RAM that perl is using?
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: Is data in RAM insecure, or am I just paranoid?
by McMahon (Chaplain) on Jul 16, 2004 at 02:52 UTC | |
by Solo (Deacon) on Jul 16, 2004 at 03:41 UTC | |
by inman (Curate) on Jul 16, 2004 at 14:32 UTC |