<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <br>
    <div class="moz-cite-prefix">On 5/17/2019 2:29 AM, Vitor Jesus
      wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CALmiUjCLy-6+RDN200OMiVD=e1g_qW0z==5dnhJcgWYwDqCNKQ@mail.gmail.com">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div dir="auto">
        <div>you can use Shamir thresholds for that but I have never
          seen any commercial software doing it.</div>
        <div dir="auto"><br>
        </div>
        <div dir="auto">It should not be too hard to develop a simple
          utility that joins the 2 keys into one accepted by a password
          manager. It just needs a bit of a well-define secure
          procedure.</div>
        <div dir="auto"><br>
        </div>
        <div dir="auto">v</div>
        <div dir="auto"><br>
        </div>
        <div dir="auto"><br>
        </div>
        <div dir="auto">---</div>
        <div dir="auto">Vitor Jesus</div>
        <div dir="auto"><a href="http://www.vitorjesus.com"
            moz-do-not-send="true">http://www.vitorjesus.com</a></div>
        <div dir="auto"><br>
        </div>
        <div dir="auto"><br>
          <br>
          <div class="gmail_quote" dir="auto">
            <div dir="ltr" class="gmail_attr">On Fri, 17 May 2019, 06:41
              Allen Schaaf, <<a
                href="mailto:netsecurity@sound-by-design.com"
                moz-do-not-send="true">netsecurity@sound-by-design.com</a>>
              wrote:<br>
            </div>
            <blockquote class="gmail_quote" style="margin:0 0 0
              .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi
              folks,<br>
              <br>
              I'm looking for a program or file system to run on Windows
              <br>
              7/8.1/10 to keep data protected that requires two separate
              keys <br>
              used at the same time to open the file. It needs to be
              like the <br>
              missile launching system that was created using two
              physical keys <br>
              at the same time to prevent one crazy person from starting
              a war.<br>
              <br>
              The goal for the credit union is to encrypt login
              information <br>
              used by the staff.<br>
              <br>
              Each of the staff has six or seven user names and
              passwords for <br>
              various local and remote systems. The manager/CEO and
              assistant <br>
              manager need to enable access to each account when either
              there <br>
              is a potential problem or when they are not available. One
              <br>
              example of this need is that US law requires each employee
              to <br>
              take a minimum one week vacation so that any fraudulent
              behavior <br>
              will be interrupted and also that the transaction they did
              can be <br>
              audited without them overseeing the audit process.<br>
              <br>
              I recall that there is a system like this but I'm unable
              to find <br>
              it. Given that it is a very small credit union and that it
              <br>
              functions in a lower income market it would be best if it
              was <br>
              free or low cost.<br>
              <br>
              I'm President of the BoD and the primary tech support
              person in <br>
              my retirement.<br>
              <br>
              Thanks,<br>
              <br>
              Allen<br>
              <br>
              ---<br>
              This email has been checked for viruses by Avast antivirus
              software.<br>
              <a href="https://www.avast.com/antivirus" rel="noreferrer
                noreferrer" target="_blank" moz-do-not-send="true">https://www.avast.com/antivirus</a><br>
              <br>
              _______________________________________________<br>
              The cryptography mailing list<br>
              <a href="mailto:cryptography@metzdowd.com" target="_blank"
                rel="noreferrer" moz-do-not-send="true">cryptography@metzdowd.com</a><br>
              <a
                href="http://www.metzdowd.com/mailman/listinfo/cryptography"
                rel="noreferrer noreferrer" target="_blank"
                moz-do-not-send="true">http://www.metzdowd.com/mailman/listinfo/cryptography</a></blockquote>
          </div>
        </div>
      </div>
    </blockquote>
    <br>
    Hi Vitor and the rest of you, <br>
    <br>
    Thanks for the various responses. It is quite helpful in clarifying
    my thinking.<br>
    <br>
    Not being a programmer, some of the answers are beyond me, alas.<br>
    <br>
    One thing that I now realize that I did not include is the need for
    more than just two people to access the file. Just for discussion,
    lets assume that there are five people, A, B, C, D, E, with an
    access key. What is needed is one of the ten combinations to cover
    the the presence/absence issues. So A/B, A/C, A,D, A/E, B/C, B/D,
    B/E, C/D, C/E, D/E, all ten possibilities would cover presence
    possibilities.<br>
    <br>
    Thanks,<br>
    <br>
    Allen<br>
    <br>
  <div id="DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br />
<table style="border-top: 1px solid #D3D4DE;">
        <tr>
        <td style="width: 55px; padding-top: 13px;"><a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient&utm_term=icon" target="_blank"><img src="https://ipmcdn.avast.com/images/icons/icon-envelope-tick-round-orange-animated-no-repeat-v1.gif" alt="" width="46" height="29" style="width: 46px; height: 29px;" /></a></td>
                <td style="width: 470px; padding-top: 12px; color: #41424e; font-size: 13px; font-family: Arial, Helvetica, sans-serif; line-height: 18px;">Virus-free. <a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient&utm_term=link" target="_blank" style="color: #4453ea;">www.avast.com</a>
                </td>
        </tr>
</table><a href="#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2" width="1" height="1"> </a></div></body>
</html>