EncFS biztonsági audit

This document describes the results of a 10-hour security audit of EncFS 1.7.4. The audit was performed on January 13th and 14th of 2014.

[...]

This audit finds that EncFS is not up to speed with modern cryptography practices. Several previously known vulnerabilities have been reported [1, 2], which have not been completely fixed. New issues were also discovered during the audit.

The next section presents a list of the issues that were discovered. Each issue is given a severity rating from 1 to 10. Due to lack of time, most issues have not been confirmed with a proof-of-concept.

A teljes dokumentum itt olvasható.