November 18, 2008
Home
About
Submit Press Release
PR Firms
Editors/Journalists
Search Archives
 
News Releases by Category  
News by Country  
News by MSA  
All News for Today  
Browse News by Day  
News by Trackbacks  
All Press Releases for June 21, 2007 Subscribe to this News Feed  
 

Elcomsoft Discovers a Quicken Backdoor, and Provides Instant Removal of Quicken Passwords

Download this press release as an Adobe PDF document.

Elcomsoft, a leader in password recovery for major Windows applications, has discovered a backdoor in Intuit's Quicken software. Millions of people worldwide have chosen Quicken as their financial software, in part because of Intuit's assurances that they have taken the steps to protect the privacy of their data by means of a highly secure password system. The latest version of Elcomsoft's Advanced Intuit Password Recovery allows businesses and individuals to remove password protection from Quicken files.

Moscow, Russia (PRWEB) - June 21, 2007 - ElcomSoft, a leader in password recovery for major Windows applications, has discovered a backdoor in Intuit's Quicken software. Millions of people worldwide have chosen Quicken as their financial software, in part because of Intuit's assurances that they have taken the steps to protect the privacy of their data by means of a highly secure password system. The latest version of Elcomsoft's Advanced Intuit Password Recovery allows businesses and individuals to remove password protection from Quicken files.

ainpr.jpg

Elcomsoft, a respected leader in the crypto community, needed to use its advanced decryption technology to uncover Intuit's undocumented and well-hidden backdoor, and to successfully perform a factorization of their 512-bit RSA key.
Beginning with Quicken 2003, Intuit protected its Quicken files with very strong encryption. This protection made it impractical for people to use brute force techniques to discover passwords that would unlock Quicken files.

It appears, however, that Intuit included a backdoor in the product, from Quicken 2003 through Quicken 2007. This backdoor allows Intuit to offer their own affordable service whereby Intuit will unlock a customer's file. To deliver this service, Intuit uses a 512-bit RSA key known only to Intuit. Before Elcomsoft's discovery of Intuit's backdoor, Intuit was the only organization that could unlock their customers' files.

"It is very unlikely that a casual hacker could have broken into Quicken's password protection regimen," said Vladimir Katalov, Elcomsoft's CEO. "Elcomsoft, a respected leader in the crypto community, needed to use its advanced decryption technology to uncover Intuit's undocumented and well-hidden backdoor, and to successfully perform a factorization of their 512-bit RSA key."

Perhaps Intuit included the Quicken backdoor to make it possible for the United States Internal Revenue Service (IRS), FBI, CIA, or other law-enforcement and forensics organizations to use an "escrow key" to gain entry into password-protected Quicken files. Unfortunately, the existence of such a backdoor and escrow key creates a vulnerability that might leave millions of Quicken users worldwide with compromised bank account data, credit card numbers, and income information.

As a service to the community, Elcomsoft has sent an official vulnerability report to CERT. CERT, which is sponsored primarily by the US government's Department of Defense and Department of Homeland Security, is responsible for responding to major security incidents an analyzing product vulnerabilities. CERT was created following the 1988 Morris worm incident which disabled more than ten percent of the Internet.

Advanced Intuit Password Recovery, and all of Elcomsoft's decryption software, runs under Windows NT4/2000/XP/2003/Vista. For more information, please visit http://intuit.elcomsoft.com .

Evaluation Copy Available on Request

About Elcomsoft Co. Ltd.

Since 1990, Elcomsoft Co. Ltd. has been developing and marketing password recovery, forensics, and security software for Windows. In addition to Advanced Intuit Password Recovery and Distributed Password Recovery, the company also offers a comprehensive line of password recovery and password auditing software for popular Microsoft, Lotus, Corel and Adobe software, as well as dozens of popular email clients, compression programs, instant messenger applications, and other applications.

###

Trackback URL: http://www.prweb.com/pingpr.php/UHJvZi1IYWxmLU1hZ24tQ291cC1UaGlyLVplcm8=


See the original story at: http://www.prweb.com/releases/quicken/backdoor/prweb534367.htm
Other Releases by this Member
Email this story to a colleague
Printer Friendly Version
Bookmark with del.icio.us
Bookmark with Y!MyWeb
Submit to Digg
Dmitry Harchenko
ElcomSoft Co.Ltd.
+7 495 974-1162
Email us Here

There are no multimedia files attached to this release. If this is your release you may add images or other multimedia files through your login.

If you have any questions regarding information in these press releases please contact the company listed in the press release. Please do not contact PRWeb. We will be unable to assist you with your inquiry. PRWeb disclaims any content contained in these release. Our complete disclaimer appears here.
 
Disclaimer: If you have any questions regarding information in these press releases please contact the company listed in the press release.
Please do not contact PRWeb®. We will be unable to assist you with your inquiry.
PRWeb® disclaims any content contained in these releases. Our complete disclaimer appears here.

© Copyright 1997-2007, Vocus PRW Holdings, LLC.
Vocus, PRWeb and Publicity Wire are trademarks or registered trademarks of Vocus, Inc. or Vocus PRW Holdings, LLC.

Terms of Service | Privacy Policy | Copyright