free software downloads SofoTex.com
Top Downloads | Featured downloads | Freeware | New | Reviews   
 Find Software      Advance search     Follow SofoTex on TwitterSofotex Rss Feeds
You are here » Windows : CryptoHeaven for Java(tm) Review

CryptoHeaven for Java(tm) reviews

CryptoHeaven for Java(tm) download




12 of 29 people found the following review helpful for CryptoHeaven for Java(tm).

5 Star Rating CryptoHeaven rocks!, Tue Aug 13 2002
Reviewed By: nirv

nirv
Good Points:
Excellent privacy, encryption and security. 256-bit encryption for all messages.

Bad Points:
Software is more then just instant messaging, so the download is relatively large. But it can be as small as 1.8 MB, depending on the OS.


General Comments:

Looking at the CryptoHeaven source code (downloadable at the CH web site ) I can confirm that all of the messages and files stored on the server are in an encrypted form. Too bad the server code is not available, but noone wants to work for free so I can understand that...

Basically the administrators of the system have no way of knowing what is being stored on the servers because all root keys in the encryption chains end up on customer's PCs (always encrypted) or stored encrypted with customer's own passphrases which never leave their computers, nor are stored anywhere. As far as I can tell, this is a major difference between CryptoHeaven and most other online storage providers which only make the connectivity SSL secure, but not the data residing on the servers to which sys admins have access to.

The system looks to be one of a few which really delivers the level of security it claims leaving little unsaid. Although it seems possible to privately implement additional algorithms like ECC and use it to communicate with your buddies (because the code is freely available), the copyright forbids it, and there are good reasons for that too. What I would like to see is integration with PGP so that we can start sending and receiving secure mail with an already established PGP user base.

I have read somewhere that symmetric key length and hash length used are not equivalent in their cryptographic strength. This claim is irrelevant as the hash seems to be used "for display purpose only" and not in the security protocols. I have yet to see a non-encrypted hash of anything on the system, so this looks good too.

Interesting is that they cannot reset your password in case you lose it. My explanation for this is because your private key (if stored on the server) is encrypted with the hash of your password, so you must have your original password to be able to decrypt your private key. If they were to reset it, your private key would have to be re-crypted with the hash of your new password, but to do that you still need the old password to decrypt it in the first place. Cleaver.

Passwords are often the weakest links in security and to rectify that, YOU CAN STORE YOUR PRIVATE KEY LOCALLY (always encrypted). This is something that is not possible with systems like Hushmail and many others.

Perhaps ability to sign other's keys and revoke signatures would create additional web of trust, but, oh well, you can't have everything.

The functionality is great; someone wrote they are putting 'all the eggs in one basket', however it may be an attempt to do just that, there is still long way to go. Never less, it is a very usable and user-friendly product which is much more than just online storage!


Was this review helpful to you?    

CryptoHeaven for Java(tm) Review Summary

100% Times: 0 Times: 0 Times: 0 Times: 0 Times: 1
80%
60%
40%
20%
0%
Times  0 0 0 0 1
Rating  1 2 3 4 5

Add your own Review!

Categories
Antivirus
Business Software
Communication
Drivers
Education
Email Utilities
File Management
FTP Software
Games
Graphics Software
Home And Desktop
Internet
Medical Software
Miscellaneous
MP3 Software
Multimedia
Networking
PC Utilities
Programming
Screen Savers
Security
Webmaster Tools
Wireless And PDA

Premiere Downloads
DVDCloner
Now what you will get are real dvd movies. Fool proof! Backup DVD with just one click!

CleanMyPC registry cleaner
Helps you get rid of the bloat in Windows registry and achieve a cleaner, faster system.

Pool Buddy Yahoo
Auto Aimer for Yahoo Pool. Detects the ball you are trying to shoot and predicts where it will go!

Advanced SystemCare Free
One-click approach to help protect, repair and optimize your computer.



Home | Developer Center | Link to Us | RSS Feeds | Hot Downloads | Contact Us | @twitter | Privacy Statement

Copyright © 1999-2009 SofoTex Inc - All rights reserved.