Re: decryption without a password key



"Amy" <Amy@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:283D3376-0F15-4FAE-B9CD-8B33EC4786C0@xxxxxxxxxxxxxxxx


"Patrick Keenan" wrote:

"Amy" <Amy@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8902292C-B94C-4419-910E-A0BDE291D4DD@xxxxxxxxxxxxxxxx
Is there a possible way to decrypt files without a password key??? I
formatted my PC and forgot to save the key...I know that you dont
believe
me
but its the truth, I swear.

So you're trying to decrypt the encrypted backup? You used EFS?

EFS relies on the account credentials. The "password key" isn't enough.
If you invoke EFS, you must export the account credentials and store them
securely. Unfortunately, this step is not mandatory.

There are some alternate methods involving a designated recovery agent.
However, it's unlikely that this was done, and it's much too late now.

For the most part, if you don't have the certificates, and can't get
them,
the data is not retrievable.

Sorry, there are very seldom happy endings to this question.

HTH
-pk


EFS? Whats that?

EFS is the XP Encrypting File System. If you used the built-in XP
encryption, this is what you used.

Alternately, you encrypted with a 3rd party product, or, you did not
encrypt the data, but merely marked it private.

And if you just marked it private, google "Take Ownership XP" and this will
tell you how to regain access rights.

Marking private, however, is *not* encrypting data; it's a totally different
thing.

I know

I'm not actually sure that is correct. You may hope that this is the case,
but your hope is not actual knowledge.

that someone knows how to decrypt without a key,

If you did use XP EFS encryption but do not have the certificates and did
not designate a recovery agent, you could maybe ask for time on NSA systems.

That's about the start of where recovery becomes a possibility. And this
will probably not be characterised as inexpensive or practical.

even you maybe,

Yes, that's why I am telling you the methods - and where they end.

but people dont wanna talk about that because they
dont wanna get fired or something but there is a way I know

Yes, there is. And that way is to import the certificates that you backed
up when invoking encryption the first time. Or, by connecting to the
recovery agent system.

Otherwise, the short answer is no. The data is gone.

Virtually every time a question like yours is posted, the data is
permanently irretrievable, because the user did not complete the tasks
needed to provide a way to decrypt the data.

...4 sure there is...

Sorry, but XP encryption is very strong, and if you used it but did not back
up the certificates or designate a recovery agent, consider the data
permanently gone, and move on.

MS did a great job at making strong encryption easily available. They
didn't do such a great job at making clear the consequences or
responsibilities that go with it.

You should do the reading on the EFS system, if it is in fact what you used.
It is excellent protection, but it carries risks and imposes
responsibilities on the users who choose to invoke it.

But again, you may simply be mistaking ownership and permissions for
encryption.

HTH
-pk


.



Relevant Pages

  • Re: decrypting files from XP - tough question
    ... EFS uses a hybrid asymmetric/symmetric encryption scheme. ... It is to those keys which EFS encrypted the ... That session key can only be retrieved by those same certificates. ...
    (microsoft.public.security)
  • Re: file security
    ... When enabling EFS on a computer, ... Subject: Again with the Encryption! ... >Copying saved certificates will not work--you have to export and import ... >the usual enquirer might find by looking under a search on Encryption. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Question, how do I decrypt data files without encryption key?
    ... Next time, I will avoid EFS ... the EFS decrypy key must be located in a hidden file ... how do I decrypt data files without encryption ... as well not having created a Recovery Agent (with ...
    (microsoft.public.win2000.security)
  • Re: Windows XP -- encrypt, decrypt -- I am in deep TROUBLE -- HELP
    ... Most of the time people post regarding EFS, it's a story without a happy ... MS did a great job of making strong encryption available, ... I'm just beginning to look into encrypted folders or entire drives and ... though it would be a good idea to re-export certificates. ...
    (microsoft.public.windowsxp.general)
  • Re: decrypt my encrypted files
    ... If you use EFS, and since you are the admin of your own host, you are expected to read ALL the help articles in the included help regarding EFS. ... You then import that EFS certificate so the files that were encrypted using it can be decrypted using that same certificate. ... You can also designate another recovery agent to recreate the EFS cert for you, but you probably didn't do that, either. ... There is no backdoor to EFS if you don't have the cert to import or a recovery agent and there is no backdoor to TrueCrypt's password encryption. ...
    (microsoft.public.windowsxp.security_admin)