Re: ZIP Encryption



"Johnnie Norsworthy" <jln206@xxxxxxxxxxx> wrote:

A customer has asked me for higher encryption than "standard ZIP". Does
anyone know what encryption levels are used for ZIPs to remain compatible
with popular ZIP decompressors?

To overcome the weakness of the "standard ZIP" encryption, WinZip devised a
slightly modified ZIP file format with support for much stronger AES encryption,
named AE-1. WinZip first implemented AE-1 in version 9.0 Beta 1, released May
2003.

Although AE-1 is not an official standard, WinZip published the AE-1
specifications so other ZIP software could follow suit.

The first Delphi component to implement the WinZip AE-1 compression was
DIZipWriter 2.0 (http://www.yunqa.de/), released Apr 2005. DIZipWriter writes
WinZip compatible ZIP files with 128, 192, or 256-bit AES encryption.

ZIP-files with strong AE-1 encryption created by DIZipWriter can be opened and
extracted by any WinZip version starting with version 9.0 Beta 1. Additional
decompression software includes the popular 7-zip archiver, starting from
version 4.43 Beta, released in Sep 2006.

Growing interest and support makes me believe in the future of the WinZip AE
strong encryption ZIP file format. Unless you are free to choose another file
format but ZIP, I would recommend this for both its open standard as well as
free, liberal-license implementations.

Ralf

---
The Delphi Inspiration
http://www.yunqa.de/delphi/
.



Relevant Pages

  • RE: Winzip and Due Diligence
    ... I would not describe this as a weakness of Winzip, ... encryption programs would be similarly vulnerable including RAR and PGP disk ... cracking WinZip passwords. ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: File encryption software?
    ... It normally takes me less than 10 minutes to break a WinZip password. ... Encryption is one of those areas where what you don't know really will hurt you. ... of such details - and have been verified by expert crypto people. ... those areas where almost all failures are fail-dangerous. ...
    (rec.outdoors.rv-travel)
  • Re: File encryption software?
    ... It normally takes me less than 10 minutes to break a WinZip password. ... Encryption is one of those areas where what you don't know really ... Crypto is one of those areas where almost all ... Like a nice deadbolt lock, it keeps the honest man honest, and slows the ...
    (rec.outdoors.rv-travel)
  • Re: Putting a Password
    ... One easy way is to use WinZip. ... Keep in mind that this isn't ... consider using third-party encryption. ... This will allow you to create a folder to store all of your ...
    (microsoft.public.windowsxp.general)
  • Re: ZIP Encryption
    ... WinZip, in the past have been found wanting when it comes to security ... To overcome the weakness of the "standard ZIP" encryption, ... slightly modified ZIP file format with support for much stronger AES ... Although AE-1 is not an official standard, ...
    (borland.public.delphi.thirdpartytools.general)