??? 03/23/08 05:46 Read: times |
#152454 - ZIP encryption has been broken... Responding to: ???'s previous message |
"Classic" ZIP encryption has been broken for 14 years. See: http://cypherpunks.venona.com/date/1994...00566.html
This technique uses known plaintext, which is usually easy to get if there are a lot of encrypted files in the ZIP. It's a practical attack, and is included in a lot of the password recovery packages. I have personally used this technique to decrypt ZIP archives (to show management that ZIP encryption really is broken). Since May 2003 WinZIP 9.0 has supported AES encryption, which is presumably breakable by password bruteforce only (if implemented properly). However, I'm not sure if this new encryption is widely supported by other ZIP tools. |