Strength of Zip archive password

dc2000

New member
Member
VIP
Local time
4:01 AM
Messages
153
I like making backups of my files on cloud services, for instance SkyDrive and Dropbox. (I have their apps running on my Windows 7 machine that sync two of my local folders.) But the question that I always had in mind is -- what about security of those services? It doesn't seem like either of them provide any encryption for its free accounts.

So what I came up with is a solution to use WinRAR to zip my files into a password protected Zip file before letting it to be uploaded to the cloud. For that I use a password, similar to something like this: "SomRaNdemWerdz23448"

So the question I have, how easy is to to break into a Zip archive created on a Windows 7 system that is protected with a decent-length password?
 

My Computer My Computer

At a glance

Windows
OS
Windows
Encryption
.ZIP supports a simple password-based symmetric encryption system which is documented in the .ZIP specification, and known to be seriously flawed. In particular it is vulnerable to known-plaintext attacks which are in some cases made worse by poor implementations of random number generators.[26]
New features including new compression and encryption (e.g. AES) methods have been documented in the .ZIP File Format Specification since version 5.2. A WinZip-developed AES-based standard is used also by 7-Zip, XCeed, and DotNetZip, but some vendors use other formats.[27] PKWARE SecureZIP also supports RC2, RC4, DES, Triple DES encryption methods, Digital Certificate-based encryption and authentication (X.509), and archive header encryption.[28]
File name encryption is introduced in .ZIP File Format Specification 6.2, which encrypts metadata stored in Central Directory portion of an archive, but Local Header sections remain unencrypted. A compliant archiver can falsify the Local Header data when using Central Directory Encryption. As of Version 6.2 of the specification, the Compression Method and Compressed Size fields within Local Header are not yet masked.

Zip (file format) - Wikipedia, the free encyclopedia

Personally, I prefer 7ZIP and its .7z format, which uses 256 bit AES encryption.

7z - Wikipedia, the free encyclopedia
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
I once experimented with a "rar password cracker" on a Winrar file I made for the purpose. It wasn't a particularly strong password but the software said it would have taken over 2 years of searching to find it. I suspect that serious decrypters and hackers have much more sophisticated programs than a free one.

I also trust and use 7-Zip for anything sensitive in nature.
 

My Computer My Computer

At a glance

Windows 7 Ultimate X64 SP1Intel i5-2550K, Differing ~4.4-4.8GHz No buil...16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GBASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built Desktop By DataTech
OS
Windows 7 Ultimate X64 SP1
CPU
Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU
Motherboard
ASUS P8Z68-V PRO/GEN3
Memory
16GB G.Skill Sniper 1866MHz @ 2133MHz 2x8GB
Graphics Card(s)
ASUS GTX650TIB-DC2OC-2GD5, (650TI Boost)
Sound Card
Onboard Realtek 5-1
Monitor(s) Displays
Samsung P2570HD
Screen Resolution
1920x1080
Hard Drives
Samsung 840 Pro 256GB SSD for OS, 500GB Seagate Constellation (Enterprise drive) for Data
PSU
Corsair HX650W
Case
Inwin Dragon Rider
Cooling
Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM
Keyboard
E-Z Eyes, bright yellow keys with large characters
Mouse
steelseries SENSEI Laser Pro Gaming
Internet Speed
48-51Mbs Mbs down, 11 Mbs up Xfinity Cable
Antivirus
Norton Internet Security 2013
Browser
IE 10, Opera, Pale Moon if needed
Other Info
4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power supply, 1.21 gigawatts.
An alternative may be to use a serious, specialized encryption program to handle the security and keep WinRar/7Zip/whatever for compression only. What I would do is to pack the files with WinRar at highest compression, but unencrypted, then store the .rar file in a TrueCrypt container that provides strong security, and upload the container instead.

Anyway, if your data is so important and confidential, I would think twice before uploading anywhere. No matter how strong it is, encryption algorithms can ALWAYS be reversed, given the time and processing power, and by having your files in someone else machine you effectively lose control on who can get it. For really critical data, keep it with yourself, and backup only to devices and computers you can physically control. Encryption makes sneaking harder, but ultimately possible, so you're giving all the info away regardless.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Core i7-740QM8 GB DDR3NVIDIA GeForce 330GT
Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Sattelite A665-S6092
OS
Windows 7 Ultimate x64
CPU
Intel Core i7-740QM
Memory
8 GB DDR3
Graphics Card(s)
NVIDIA GeForce 330GT
Screen Resolution
1366x768
Hard Drives
Samsung 840 SSD 500GB
1TB USB3 external HD
Cooling
Coolermaster Notepal U3 notebook cooling pad
Internet Speed
3mbps ASDL
Antivirus
ClamWin 0.98.7
Browser
Opera 12.17 x86 (main), Firefox 38 (sec), IE11 (last resort)
Back
Top