4 ms·
That's a fair point. I previously supported -p|--password followed by a password, but I removed that functionality in a later version because strings are immuta
by samuel-lucas6 5y ago
That's a fair point. I previously supported -p|--password followed by a password, but I removed that functionality in a later version because strings are immutable in .NET and therefore cannot be zeroed out from memory. Furthermore, I think hiding the typed password characters is beneficial from a security perspective.
Whilst that functionality could be added back in, I'm trying to keep the number of options as small as possible. Kryptor already has more options than age because it supports signatures. Having two password related options also adds confusion, and it would be slightly more tricky to support batch functionality for decrypting your private key.
- tyingq 5y agoI think getting rid of providing the password as a plaintext command line parameter makes sense. Accepting it on a file handle or stdin seems like it would be popular though.