tag:infinitekind.tenderapp.com,2009-01-14:/discussions/iphone-ipod-touch-ipad-android-app-questions/354-how-does-the-new-ios-app-read-encrypted-filesInfinite Kind: Discussion 2015-03-31T16:14:49Ztag:infinitekind.tenderapp.com,2009-01-14:Comment/169537342012-06-28T14:18:04Z2012-06-28T14:18:04ZHow does the new iOS app read encrypted files?<div><p>Hi KT,</p>
<p>We share your thoughts on security- after all we all use
Moneydance and the app every day! Your finances are some of the
most private information in your online life. Although Dropbox
encrypts your data on the server, this wasn’t good enough for
us. All Moneydance data that is synced over Dropbox is additionally
encrypted using a 128 bit AES key that you specify on your desktop
and on each device. This ensures that your data is completely safe,
even if the bad guys get access to your Dropbox account.</p>
<p>If you have any other questions, please don't hesitate to
ask,</p>
<p>Angie Rauscher<br>
Moneydance Support</p></div>Angie Rauschertag:infinitekind.tenderapp.com,2009-01-14:Comment/169537342012-06-28T14:51:50Z2012-06-28T14:51:50ZHow does the new iOS app read encrypted files?<div><p>Understood. But how does it access my encrypted Moneydance file
without asking for the same encryption password that the desktop
application requests?</p>
<p>Just to be clear here, I am NOT talking about the password that
the Network Synchronization Extension requested. I'm talking about
the file encryption password that I set via the desktop
application. If my file is encrypted and the desktop application
requests a password, how does the iOS app access it without ever
requesting that password?</p></div>KTtag:infinitekind.tenderapp.com,2009-01-14:Comment/169537342012-06-28T14:57:12Z2012-06-28T14:57:13ZHow does the new iOS app read encrypted files?<div><p>Let me elaborate. I set up my Moneydance file in the desktop
application (File->Encryption...) and I set a password of
foobar123. Every time I start the desktop application, I must enter
foobar123 in order to work with the file.</p>
<p>OK, now I set up the iOS app. The Network Synchronization
extension wants a password. I enter snafu678. When I set up the IOS
app, it wants a password. I entered snafu678. Voila, the file is
opened and it shows me data. It never made me enter foobar123
anywhere.</p>
<p>Why did the iOS app never request the foobar123 password that
the desktop application requires? If the file is encrypted with
that password, how can the iOS app access it without ever being
told that password?</p></div>KTtag:infinitekind.tenderapp.com,2009-01-14:Comment/169537342012-06-28T22:04:06Z2012-06-28T22:04:06ZHow does the new iOS app read encrypted files?<div><p>All of the information that goes through dropbox is encrypted
with the sync password.</p>
<p>When you first set up the sync the initial sync you had already
entered your main password and decrypted your data into memory.
This data was written to dropbox and encrypted with your sync
password - snafu678. This was then decrypted by the mobile app
using the sync password.</p>
<p>The iOS app never has direct access to your encrypted .md file.
All it has access to is is change files that are written to dropbox
and encrypted with the sync password.</p>
<p>Ben Spencer<br>
Moneydance Support</p></div>Ben Spencertag:infinitekind.tenderapp.com,2009-01-14:Comment/169537342012-06-29T03:36:43Z2012-06-29T03:36:44ZHow does the new iOS app read encrypted files?<div><p>Ben,</p>
<p>Thank you. That clarifies it for me. I didn't realize that the
iOS app doesn't have access to the encrypted .md file.</p></div>KTtag:infinitekind.tenderapp.com,2009-01-14:Comment/169537342012-07-29T21:22:08Z2012-07-29T21:22:09ZHow does the new iOS app read encrypted files?<div><p>This was a very enlightening thread for me. Just to make sure
I'm clear about KT's scenario:</p>
<p>-The .md file is encrypted locally using 3DES -The sync file is
encrypted to Dropbox using AES128</p>
<p>Since 3DES is theoretically less secure than AES, storing the
.md file in a local folder that syncs to Dropbox would potentially
place the .md file at greater risk than the sync file, right? So
until AES encryption is available in the next MD release, is there
a way to store the .md file locally (NOT in a location that syncs
to Dropbox) - and still have a sync file on Dropbox - to improve
.md file security? Assuming, of course, that the user properly
safeguards the local .md file! ;-)</p>
<p>Thanks!<br>
Kent</p>
<p>PS: I'm quite pleased with the new Dropbox sync on the iOS app.
It was worth the wait.</p></div>Kenttag:infinitekind.tenderapp.com,2009-01-14:Comment/169537342012-07-29T21:30:06Z2012-07-29T21:30:06ZHow does the new iOS app read encrypted files?<div><p>Hi Kent,</p>
<p>There's no issue with storing your main .md file anywhere you
want--the only data that needs to be on Dropbox are the sync files
for the iOS app, but your main .md file can be anywhere, including
just on your local computer, and it will sync up fine.</p>
<p>Please let us know if we can be of further assistance!</p>
<p>Scott Meehan<br>
Moneydance Support</p></div>Scott Meehantag:infinitekind.tenderapp.com,2009-01-14:Comment/169537342012-07-29T22:14:46Z2012-07-29T22:14:47ZHow does the new iOS app read encrypted files?<div><p>Scott,</p>
<p>Thanks! I tested this configuration and am happier with not
having my .md file on Dropbox (a holdover from when I accessed the
sile from two different PCs). I had assumed the .md file needed to
reside on Drobbox... So where does the sync (change) file reside? I
cannot locate it anywhere in my Dropbox files. Is it being stored
in another Dropbox location?</p>
<p>Thanks,<br>
Kent</p></div>Kenttag:infinitekind.tenderapp.com,2009-01-14:Comment/169537342012-07-30T00:09:44Z2012-07-30T00:09:44ZHow does the new iOS app read encrypted files?<div><p>Hi Kent,</p>
<p>All the Dropbox sync files reside in the folder:</p>
<p>.moneydancesync</p>
<p>in Dropbox. This folder is usually hidden, so you would have to
enable viewing hidden files and folders on your operating system's
file manager or, the easier way, view them using the Dropbox iOS
app or Dropbox web interface.</p>
<p>Please let us know if we can be of further assistance!</p>
<p>Scott Meehan<br>
Moneydance Support</p></div>Scott Meehan