The Mac Observer

Skip navigational links

Featured Article:

Data Guradian Stores Passwords, Credit Card Numbers, More

by , 12:00 AM EDT, September 5th, 2006

Koingo Software has released version 1.0 of Data Guardian, an application for storing passwords, credit card numbers, addresses, notes, contact information, and anything else that the user wants to keep safe from prying eyes. The software supports 448-bit encryption and integrates with Keychain for auto-filling its fields.

Pricing is US$19.95. Mac OS X v10.2 is required. Data Guardian is a Universal Binary.


Data Guardian

Observer Comments

Show: Subjects Only | Full Comments
Close Name:Rainy Day Posts: 607 Joined: 07 Jun 2005
Subject: 448-bit encryption

That’s a lot of bits.

Close Name:geoduck Posts: 1922 Joined: 30 Dec 2003
Subject:

One of my responsibilities here at work is advising people on data security. I STRONGLY advise my users against using any sort of desktop critical data storage software. It seems too much like keeping all of your eggs in one basket.

1) If the critical data is stored in a file on your computer then if someone breaks in to your machine a copy can be made of the file and the bad buys have all the time and computing power they need back at home to crack it. This is less of a problem with Macs, but on the XP machines I support it's a huge issue.

2) if you lose the password to the software then the data stored in it is useless to you. I have had users keep the ONLY copy of their passwords in packages like this. When my users forget the one they need to get into the file, they then spend the rest of their day (or in some cases several days) resetting all of their passwords. On the other hand if they keep a spare copy of the password somewhere else, then they might as well keep all of them somewhere else.

I keep my passwords on a handwritten card I keep with me. No one can grab them over the net. If they break into my machine they don't have the password for anything. If they break into my office they don't have the password for anything. If the card gets stolen they have the passwords but the card just has 50 or so character strings without any indication (that they know of) of what they go to so they still can't get anywhere.

To me this software and the similar packages for Windows are like storing all of the keys to the building in a box next to the front door and using a single padlock to secure the box. Better to keep all the extra keys in another building.

FWIW I have ~50 passworded systems I have access to and I change all of my passwords quarterly. Yes it's a pain in the @$$ but until we go to some sort of dual key authentication around here for all of our systems it's what I need to do. Even them on line sites like TMO will still have their own password that I'll have to keep with me.

Close Name:gslusher Posts: 2088 Joined: 13 Nov 2002
Subject:

Quote
geoduck wrote:

I keep my passwords on a handwritten card I keep with me. No one can grab them over the net. If they break into my machine they don't have the password for anything. If they break into my office they don't have the password for anything. If the card gets stolen they have the passwords but the card just has 50 or so character strings without any indication (that they know of) of what they go to so they still can't get anywhere.


Some good advice, but carrying passwords written on a card, etc., can violate security rules at some companies. (It would have violated security rules in the US Air Force during my career.) This was a plot device in one Law & Order-Criminal Intent episode, if I remember correctly. Someone observed a colleague using such a card and noted where she kept it, then snuck a look.

Suppose your wallet/bag/briefcase is stolen? Do you have a backup somewhere?

Close Name:geoduck Posts: 1922 Joined: 30 Dec 2003
Subject:

Quote
gslusher wrote:
Suppose your wallet/bag/briefcase is stolen? Do you have a backup somewhere?

If the card were stolen I'd just have to start resetting passwords. But I'd know I'd need to reset them. Even if someone could look at the card, or even steal it the passwords are listed in a way such that I know which PW goes with what, but no one looking at the card would.

Yes, this would violate policies in a lot of businesses or govt agencies. I'm lucky in that I set the standards for around here rather than some Policy Group that only knows what they read in the eWeek.

Comment on this Article


You cannot edit your comments.   You cannot delete your comments.
Log in | Register | Having Problems? Reset TMO Cookies & Try Again
Username:   Password:   Log me on automatically each visit   

You are not logged in, and this post will appear as "Guest." Log in with your username and password from the TMO forums. If you do not have a username, you can register here.
Please note that guests are limited to including a maximum of two URLs per post.


Post A Comment
  Subject


  Your Comments



Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.


Recent Headlines - Updated January 8th

Wed, 6:20 PM
Macworld Expo 2009 - Ecamm Introduces World’s First Bluetooth Webcam
6:16 PM
News - Verbatim Announces Speaker Keyboard, Store ‘n’ Go Micro USB Drive
6:09 PM
Photo Gallery - Photo Gallery: Macworld 2009 Day 2
3:24 PM
Just a Thought - First Time Macworld Impression
12:16 PM
News - EMC Issues Beta of Retrospect 8.0 Backup Software
12:04 PM
News - REAL Server 2009 to Ship Next Month
11:40 AM
News - Livescribe to Bring Pulse Smartpen Software to Mac
10:58 AM
Hot Forum Topic - Reader Reactions: Apple’s Macworld Expo Keynote
10:39 AM
News - Verbatim, Lexar Introduce New Flash Storage Options
10:20 AM
Editorial - Don’t shoot the messenger: Content, Not Delivery Marred Apple’s Last Keynote
9:51 AM
News - LaCie Releases 2big Quadra External Hard Drive Line
9:29 AM
News - Microsoft’s Mac Business Unit Reveals Upcoming Office Improvements

The Mac Observer Reader Specials