Saturday, April 22, 2006

Identity management on the USB thumbdrive!!

Today is the day that I have been waiting for almost a year now.  The guys at electronic liberty finally realeased Defygo, a Security Management Suite, which includes a password manager (vault), file encryption and decryption (using AES or TDES), email encryption and decryption (sent to buddies that are have a electronic liberty account, this is because of the public private key scheme used with the email encryption), Cryptograms (you can send encrypted messages to friends with electronic liberty accounts), and update features.

I have been using Defygo for a while now as a pre-realease user.  Defygo itself is a program that is almost a front-end to a web storage for you accounts.  It uses SSL encryption to encrypt the traffic between itself and the servers.  The passwords that you put up on the servers using Defygo are encrypted so Electronic Liberty does not know your passwords.

I know what you are saying how can this be secure if all my passwords are in one place with one password to protect them.  I said this very thing, but you are mistaken, instead of one password there are actually two.  The first password you enter is your electronic liberty username and password, the next you enter in is your defygo security key which you create the first time you use defygo.  Basically someone would have to guess these two passwords in order to get into the password manager; however, the thinking behind this is that not only will you use a strong password but because you are storing them in a place that always has your passwords you can then setup stronger passwords on your accounts that you use in your daily lives.  Which means stronger and better passwords all the way around. 

If you don't like the idea of putting your passwords up on the web (wait you already do that everywhere else!!!!) the passwords that you pass up are an encrypted form of your passwords (this is not a hash but an encrypted version check the website for what they use.)  This means that the guys at electronic liberty have no idea what your passwords, usernames, website associated, or any other information you put in about an identity in the vault.

Defygo is probably the best portable app that I have on my thumbdrive and soon I hear they might come out with a web version which you can use to manage your passwords and other items like email encryption, file encryption from the web. 

In short check, Defygo out look at the screenshots and decide for yourself if you would like to try to be more secure by using something that allows you to create stronger passwords.

No comments: