3 ms·
Great feedback, I'll change the "how to" ASAP after some reading on the subject. Is there a secure command option that I can use with openssl instead of -aes-25
by nanch 14y ago
Great feedback, I'll change the "how to" ASAP after some reading on the subject. Is there a secure command option that I can use with openssl instead of -aes-256-cbc?
I originally tried to provide an example for openssl and gpg, but the gpg example ended up with a dependency on X11 via a dependency on pinentry so I took it out for simplicity.
- JoachimSchipper 14y agoOpenSSL sadly does not offer any authenticated encryption modes, so you cannot just replace -aes-256-cbc by something and be secure. There are basically two things that work: either authenticate the ciphertext [1] by having the user store a secure hash of each archive ("openssl sha512"), or switch to public-key crypto. Since the first is just inviting disaster - users aren't actually going to verify hashes - I recommend the second option. It's possible to build this on top of "openssl pkeyutl", but gpg is a lot nicer. If I were you, I'd just use gpg - some OSes/distros may pull in lots of stuff, but requiring a running (as opposed to installed) X server to run gpg is incredibly unlikely. [1] Always authenticate the ciphertext, never (just) the plaintext. See "padding oracle attack" for one practical reason why - getting a recognizable error when decrypting mangled ciphertext allows one to fully recover the plaintext. "Recognizable error" includes timing information. Just make sure you always authenticate the ciphertext.