Repository navigation
Release v1.2.0
·
9 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Full Changelog: v1.1.0...v1.2.0
Cryptare v1.2.0
This release changes how new data is encrypted, and fixes a number of security issues and bugs found in a full review. Read "Upgrading" before you install it on one machine and not the others.
Highlights
- New encrypted format. Files, folders, stored keys and key exports are written in a versioned format: Argon2id (64 MiB, 3 passes, 4 lanes) instead of PBKDF2, and authenticated 64 KiB chunks, so memory use no longer grows with file size. Everything written by older versions still decrypts.
- Passwords off the command line:
--password-fileonencrypt,decryptand thekeyscommands.--passwordstill works but prints a warning. - New passwords need at least 15 characters and are typed twice at a terminal.
- Nothing is overwritten by default. Add
--forceto replace an existing output. That includeskeys export, which never writes over the key store. A failed or interrupted command leaves no partial output. - Stopping is safe: Ctrl+C,
killor a closed terminal stops a command and removes its unfinished output. The exit status is 128 + the signal (130 for Ctrl+C). Quitting the TUI cancels a running action first. - Extraction limits guard against decompression bombs (10 GiB and 100,000 entries by default;
--max-size,--max-entries). decompress --rawgunzips a file without extracting it, sox.tar.gzgivesx.tarback.- File and folder names in any script (Chinese, Cyrillic, emoji, …) now work with gzip and folder encryption.
Security fixes
- Builds use Go 1.26.8. v1.1.0 was built with Go 1.26.0, whose
archive/tarcould be made to allocate memory without bound by a crafted archive (GO-2026-4869). - Extraction writes only inside the output folder (
os.Root) and ignores permissions stored in archives: folders are 0700 and files 0600 on Linux and macOS. - On Linux and macOS, a key store that another user owns or that others can write to is refused. Stored key IDs are escaped when listed, so a planted key store can't inject terminal escape sequences.
- The key store's SQL statements (with encrypted key blobs) are no longer printed to stdout.
- Directory encryption no longer writes plaintext to the temp folder, and deleted keys are overwritten in the database file.
- The Docker image runs as an unprivileged user, from base images pinned by digest.
Upgrading from v1.1.0 or earlier
- Format: v1.1.0 and earlier can't decrypt files made by this version; they report a wrong password. Upgrade every machine that needs to read them.
- If you encrypted at the old interactive prompt with a multi-word passphrase (v1.0.1 or earlier), decrypt with only the first word. The old prompt kept only the text before the first space.
- Scripts that pass a password shorter than 15 characters to
encrypt,keys generateorkeys exportnow fail. decompress --forceanddecrypt --forcereplace an existing output folder instead of merging into it. Extracted files no longer keep the archive's permissions.- Archives over 10 GiB of output or 100,000 entries need
--max-sizeor--max-entries. Files in the old format are read whole, sodecryptrefuses one larger than--max-size; raise it for bigger ones. keys exportrefuses an existing file unless you add--force.encrypt dir/andencrypt .write the encrypted file next to the folder (dir.enc), not inside it. An--outputinside the folder is refused.compressrefuses a--formatthat contradicts the output's extension, and--levelvalues other than 1–9 or -1.--password ""now means an empty password instead of prompting.- A
CRYPTARE_DB_PATHcontaining?is refused; use afile:URI with%3F. - Docker: the image runs as UID 10001. For a bind-mounted data folder, add
--user "$(id -u):$(id -g)". - Windows: outputs and the key store get the permissions of the folder they're written to. Keep them in a folder only you can read.
Install
Download your platform's archive and checksums.txt, check the hash (sha256sum --ignore-missing -c checksums.txt), and put the binary on your PATH. See the README for details.