4 ms·
To encrypt: tar cz foo | openssl aes-256-cbc -salt -out foo.enc To decrypt: openssl aes-256-cbc -d -in foo.enc | tar xz (foo can be a file or directory)
by norcimo5 9y ago
To encrypt:
tar cz foo | openssl aes-256-cbc -salt -out foo.enc
To decrypt:
openssl aes-256-cbc -d -in foo.enc | tar xz
(foo can be a file or directory)
- snakeanus 9y agoThis does not contain a MAC though, does it? Also why CBC? Why not CTR/GCM instead? And why AES256 instead of Chacha20-Poly1305 or some other modern AEAD?
- norcimo5 9y agoWhat are the advantages of GCM over CBC? And whats wrong with AES256?
- kaoD 9y agoGCM has an integrity check built in, which is very useful in crypto. https://crypto.stackexchange.com/questions/2310/what-is-the-difference-between-cbc-and-gcm-mode https://crypto.stackexchange.com/questions/2310/what-is-the-... https://crypto.stackexchange.com/questions/14747/gcm-vs-ctrhmac-tradeoffs https://crypto.stackexchange.com/questions/14747/gcm-vs-ctrh... https://security.stackexchange.com/questions/33569/why-do-you-need-message-authentication-in-addition-to-encryption https://security.stackexchange.com/questions/33569/why-do-yo...
- snakeanus 9y ago- GCM unlike CBC is an AEAD mode (has a MAC build-in) - CBC needs padding, which when misused can lead to padding oracle attacks - GCM allows for parallel encryption > And whats wrong with AES256? There are more modern, faster and better ciphers that are designed to not be vulnerable against many side-channel attacks that AES is difficult to protect against.