Skip to content

v3.0.15 πŸ¦• Iguanodon β€” confirm your password is saved before encrypting

Choose a tag to compare

@seQRets seQRets released this 09 Oct 09:44
· 2 commits to main since this release

v3.0.15 πŸ¦• Iguanodon β€” confirm your password is saved before encrypting

Follows v3.0.14. The cryptography, container format,
wordlist, and self-tests are untouched; the Recovery tool's decryption core
is byte-identical to every release since v2.9.0.

Changes

  • Confirm the password is saved before encrypting. IttyBitz clears the
    password from the page the moment you encrypt, and until now the reminder
    to save it only appeared afterwards, when it was too late. Encrypt mode
    now has a checkbox above the button, I have saved this password
    somewhere safe
    , and encrypting is refused until it is ticked. The
    password stays in the field when that happens, so it can still be copied.
    The box unticks itself whenever the password changes, including after
    Generate, so a confirmation never carries over to a different password.
    Decrypting is unaffected.
  • Shorter messages after encrypting. With the checkbox in place, the
    "Store your saved password securely" line that followed every encryption
    repeated what you had just confirmed, so it is gone. The several-files
    summary no longer has blank lines between its parts.
  • Clearer key-file notice. After generating a key file, the notice no
    longer states the fingerprint twice, and now says that the fingerprint is
    shown whenever the file is selected, even if it has been renamed.
  • README corrections. It now says that weak passwords are refused (not
    merely discouraged); describes what memory clearing actually covers; says
    the in-repo security audit covers v2.8.1, before the v3 rewrite; replaces
    "upload" with "select or drop", since nothing is uploaded; and gives the
    correct build command.

For users

Nothing to do. Existing .ibitz files and encrypted text decrypt exactly as
before.