Skip to content

Release v1.2.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 19:43
· 9 commits to main since this release
Immutable release. Only release title and notes can be modified.

Full Changelog: v1.1.0...v1.2.0

Cryptare v1.2.0

This release changes how new data is encrypted, and fixes a number of security issues and bugs found in a full review. Read "Upgrading" before you install it on one machine and not the others.

Highlights

  • New encrypted format. Files, folders, stored keys and key exports are written in a versioned format: Argon2id (64 MiB, 3 passes, 4 lanes) instead of PBKDF2, and authenticated 64 KiB chunks, so memory use no longer grows with file size. Everything written by older versions still decrypts.
  • Passwords off the command line: --password-file on encrypt, decrypt and the keys commands. --password still works but prints a warning.
  • New passwords need at least 15 characters and are typed twice at a terminal.
  • Nothing is overwritten by default. Add --force to replace an existing output. That includes keys export, which never writes over the key store. A failed or interrupted command leaves no partial output.
  • Stopping is safe: Ctrl+C, kill or a closed terminal stops a command and removes its unfinished output. The exit status is 128 + the signal (130 for Ctrl+C). Quitting the TUI cancels a running action first.
  • Extraction limits guard against decompression bombs (10 GiB and 100,000 entries by default; --max-size, --max-entries).
  • decompress --raw gunzips a file without extracting it, so x.tar.gz gives x.tar back.
  • File and folder names in any script (Chinese, Cyrillic, emoji, …) now work with gzip and folder encryption.

Security fixes

  • Builds use Go 1.26.8. v1.1.0 was built with Go 1.26.0, whose archive/tar could be made to allocate memory without bound by a crafted archive (GO-2026-4869).
  • Extraction writes only inside the output folder (os.Root) and ignores permissions stored in archives: folders are 0700 and files 0600 on Linux and macOS.
  • On Linux and macOS, a key store that another user owns or that others can write to is refused. Stored key IDs are escaped when listed, so a planted key store can't inject terminal escape sequences.
  • The key store's SQL statements (with encrypted key blobs) are no longer printed to stdout.
  • Directory encryption no longer writes plaintext to the temp folder, and deleted keys are overwritten in the database file.
  • The Docker image runs as an unprivileged user, from base images pinned by digest.

Upgrading from v1.1.0 or earlier

  • Format: v1.1.0 and earlier can't decrypt files made by this version; they report a wrong password. Upgrade every machine that needs to read them.
  • If you encrypted at the old interactive prompt with a multi-word passphrase (v1.0.1 or earlier), decrypt with only the first word. The old prompt kept only the text before the first space.
  • Scripts that pass a password shorter than 15 characters to encrypt, keys generate or keys export now fail.
  • decompress --force and decrypt --force replace an existing output folder instead of merging into it. Extracted files no longer keep the archive's permissions.
  • Archives over 10 GiB of output or 100,000 entries need --max-size or --max-entries. Files in the old format are read whole, so decrypt refuses one larger than --max-size; raise it for bigger ones.
  • keys export refuses an existing file unless you add --force.
  • encrypt dir/ and encrypt . write the encrypted file next to the folder (dir.enc), not inside it. An --output inside the folder is refused.
  • compress refuses a --format that contradicts the output's extension, and --level values other than 1–9 or -1.
  • --password "" now means an empty password instead of prompting.
  • A CRYPTARE_DB_PATH containing ? is refused; use a file: URI with %3F.
  • Docker: the image runs as UID 10001. For a bind-mounted data folder, add --user "$(id -u):$(id -g)".
  • Windows: outputs and the key store get the permissions of the folder they're written to. Keep them in a folder only you can read.

Install

Download your platform's archive and checksums.txt, check the hash (sha256sum --ignore-missing -c checksums.txt), and put the binary on your PATH. See the README for details.