Releases: ryd3v/FileEncryptor
Releases · ryd3v/FileEncryptor
Release list
V2.0.2 M4 Compatibility
Version 2.0.1 Release Notes
Enhancements:
- Increased the length of the cryptographic salt used for key generation and encryption from 16 bytes to 32 bytes (256 bits) to enhance security.
- Modified the
generate_keyfunction to generate a 32-byte salt usingos.urandom(32)when no salt is provided explicitly. - Updated the
decrypt_key_filefunction to read 32 bytes for the salt from the "key" file, ensuring compatibility with the longer salt length.
Impact:
- Improved resistance against precomputation attacks and salt collisions by expanding the salt space and reducing the likelihood of salt reuse vulnerabilities.
- Increased computational cost for attackers attempting to crack hashed passwords, thereby enhancing overall security posture.
- Aligned with best practices and security guidelines recommending longer salts for password hashing and key derivation.
Considerations:
- Longer salts may impose additional storage overhead and slightly increased computational overhead during key derivation and hashing operations.
- Compatibility with existing systems, libraries, and protocols should be verified to ensure seamless integration with the updated salt length.
Recommendation:
- Users are encouraged to upgrade to version 2.0.1 to benefit from enhanced security provided by longer cryptographic salts.
FileEncryptor 2.0.0
Overview
This release of FileEncryptor introduces significant updates and enhancements, focusing on improving the handling of large files and the security of the encryption process. The application now utilizes AES-GCM for encryption, providing a more robust and efficient method suitable for large files.
New Features
- AES-GCM Encryption: Transitioned from Fernet to AES-GCM for file encryption and decryption, allowing for efficient processing of large files.
- Chunked File Processing: Implemented chunked processing for large files to prevent memory overload and application crashes.
- Progress Bar: Added a progress bar during encryption and decryption processes for better user feedback, especially useful for large files.
Enhancements
- Key Derivation: Improved the key derivation process to use PBKDF2 with SHA-256, enhancing the security of the generated keys.
- Increased Iterations: The number of iterations in the key derivation function has been increased to 750,000, significantly strengthening the resistance against brute-force attacks.
- Nonce Management: Each encryption operation now uses a unique nonce, in line with AES-GCM requirements, to enhance security.
Bug Fixes
- Key Size Issue: Resolved an issue where the key size was incompatible with AES-GCM requirements.
- Error Handling: Improved error handling and messaging throughout the application.
Breaking Changes
- Key Incompatibility: Due to the switch to AES-GCM, keys generated in previous versions are not compatible with this release. Users will need to regenerate keys.
Instructions
- For encryption:
./FileEncryptor encrypt <file_path> - For decryption:
./FileEncryptor decrypt <file_path>