3 ms·
Perhaps I'm missing something obvious, but why can't the filename be encrypted as well? (So you have public key 0xDEAFBEEF; you want to write a file named 'sec
by cfcef 11y ago
Perhaps I'm missing something obvious, but why can't the filename be encrypted as well?
(So you have public key 0xDEAFBEEF; you want to write a file named 'secret.txt' with the contents 'We attack at dawn'. OweFS encrypts 'We attack at dawn' to 010101 and writes that to 'secret.txt'. But why couldn't it have encrypted the contents to 010101 and encrypted the filename 'secret.txt' to 111000, and then written a file named 111000.encrypted with the contents 010101? Then when the owner of 0xDEAFBEEF wanted to read it, he simply decrypts 111000.encrypted to 'secret.txt' and decrypts its content 010101 to 'We attack at dawn.')
- craigds 11y agoYou could do that, but it'd be quite inefficient. Firstly, let's assume that directories aren't encrypted. Otherwise this would be a real PITA - just to locate /foo/bar/baz.txt you'd have to decrypt each component of 001001/011101/110101.encrypted separately. More importantly, the decrypting software has no way to encrypt things, only decrypt them. So to read 'secret.txt' you can't just encrypt 'secret.txt' to '111000.encrypted'. Instead, you have to iterate through the entire directory listing and decrypt every single filename, until you find one that decrypts to 'secret.txt'. Obviously this gets pretty bad with even moderately-sized directories. I assume this is why the project doesn't encrypt filenames.
- cfcef 11y agoIf you're reading files rather than writing them, then you must be decrypting them and in possession of the private key, which means you are permitted access to everything; so you could cache all the decryptions. Initial reads might be more expensive to locate, but then free. Also, how many cycles could it take to decrypt the few hundred or few thousand characters that could possibly make up a full filepath?