5 ms·
Show HN: CryptoPocket, Encrypt anything then Decrypt by providing a required key
- throwawayay02 5y agoI don't get it, what does it do? I can encrypt anything and decrypt it by providing a required key with 7zip and a myriad other programs, but the Github pictures suggest to me much more.
- mp85 5y agoHello throwawayay02, yeah, CryptoPocket has several features, including the one you mentioned :) check it out here [1] it's a small project that I found and put on GitHub in case it comes in handy for someone ;) [1] https://www.softpedia.com/get/Security/Encrypting/Crypto-Pocket.shtml https://www.softpedia.com/get/Security/Encrypting/Crypto-Poc...
- pixxel 5y agoSmall detail: the file lock icon isn’t the best choice IMO. The files can be slid out, which makes the lock useless. Not the ideal association for the product.
- mp85 5y agoHello pixxel, you are right, thanks.
- woodruffw 5y agoFrom a very quick cursory search: this is using VB's `Rnd` to generate random "keys," which is a massive warning sign[1]. `Rnd` is not cryptographically secure[2] and you should not use it for anything remotely close to key generation. Edit: I also can't find any evidence that this tool changes the default block mode for `RijndaelManaged`[3], which is CBC. Without any other mitigations (which I can't find), this makes this tool vulnerable to a chosen ciphertext attack. [1]: https://github.com/miroslavpejic85/cryptopocket/blob/main/src/Class/RandomKeyGenerator.vb https://github.com/miroslavpejic85/cryptopocket/blob/main/sr... [2]: https://docs.microsoft.com/en-us/office/vba/language/reference/user-interface-help/rnd-function https://docs.microsoft.com/en-us/office/vba/language/referen... [3]: https://docs.microsoft.com/en-us/dotnet/api/system.security.cryptography.rijndaelmanaged.mode?view=net-6.0 https://docs.microsoft.com/en-us/dotnet/api/system.security....
- mp85 5y agoI did a small changes, thanks again for the advice. All the best.
- mp85 5y agoHello woodruffw, Thanks so much for the suggestions. Any PR is welcome to improve it :)
- woodruffw 5y agoI don't know enough Visual Basic to meaningfully improve this program. I only know enough to recognize patterns that shouldn't be anywhere in a program that purports to encrypt files. I think you should put a note in the README disclaiming the cryptographic and key generation problems in this program. Not doing so is probably going to result in people relying on cryptographic properties it cannot provide.
- mp85 5y agoDon't worry, anyone like you with more experience is welcome, and anyone can feel free to improve and contribute. Thanks again for your valuable advice.
- randomhodler84 5y agoI’ll give you some more advice. Don’t write security software unless you know what you are doing. Using a non-CSPRNG for keys is a complete fail. It is dangerous for your users and shows you do not know what you are doing.
- mp85 5y agoHello randomholder84, As already mentioned it is an open source project, feel free to improve it by applying all your knowledge in that area. I accept criticisms if they are constructive. Thanks for your suggestions.