19 ms·
# Encrypt a file openssl enc -aes-256-cbc -salt -in secret.txt -out secret.enc # Decrypt openssl enc -d -aes-256-cbc -in secret.enc -out secret.txt Wow that w
by disambiguation 11mo ago
# Encrypt a file
openssl enc -aes-256-cbc -salt -in secret.txt -out secret.enc
# Decrypt
openssl enc -d -aes-256-cbc -in secret.enc -out secret.txt
Wow that was hard.
- prophesi 11mo agoI'm reminded of the infamous HN Dropbox comment.
- runjake 11mo agoReference: https://news.ycombinator.com/item?id=9224 https://news.ycombinator.com/item?id=9224
- deleted 11mo ago[deleted]
- deleted 11mo ago[deleted]
- radlad 11mo agoYeesh, this seems like a good example of the fact that a feature (encrypting a file) is not a product (an E2E encrypted storage solution.)
- exe34 11mo agoRe: rubber hose attack on cryptography.
- Zak 11mo agoThreat modeling is important of course. The UK government does have tools with which to punish people who don't turn over the cleartext of targeted documents once it's directly investigating them, but that's not scalable. The method the grandparent comment proposes greatly reduces one's exposure to mass surveillance, criminals, and abusive service providers.
- smsm42 11mo agoYou may think you're being sarcastic, but you are just stating a true fact here. For about 99.9% of this planet's population, it's not just hard, it's something they'd never ever know how to do and have no intention to ever learn. Like it or hate it, but that's what it is. And, for 99.9% of people who know how to do that, they'd still be too lazy to do it properly (hint: where do you keep secret.txt exactly? What happens if your dog eats it?) and will use some third-party solution instead.
- deleted 11mo ago[deleted]
- mystifyingpoi 11mo ago> where do you keep secret.txt Reminds me of using Ansible Vault and preciously encrypting every secret (so we can say that repos doesn't contain any secrets), then just putting ~/.vault_pass in plaintext on every Ansible controller to be taken by anyone with access to the servers.
- alexpotato 11mo agoThe author of AGE has a great point in the below blog post [0]: If you use something like SOPS or just check age secrets into a git repository next to source code, you need an authentication story for the whole repository. Having authentication for the secrets will do nothing if the attacker can change the source code that decrypts and uses them. That story can simply be “we trust GitHub” like most projects. Encrypting secrets with age will keep them confidential even if the project is Open Source, and anyone wanting to replace them will have to make a PR even if they can generate a new valid age file. 0 - https://words.filippo.io/age-authentication/ https://words.filippo.io/age-authentication/
- jcynix 11mo ago>where do you keep secret.txt exactly? Hidden. Encrypted. And the passphrase is: at 5,21 which is the 5th line on page 21 of your favorite book. Which you have more than one copy of, because you like it that much. And you need copies to lend. Or you have the PDF from Gutenberg.org? And 5/21 might be the birthday of your first child, or your wedding day, or whatever? It might be a favorite quote, like "Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety." Augmented by the above date if needed?
- subscribed 11mo agoNice. Now explain how my mum can select that in settings of her phone, thx.
- NetMageSCW 11mo agoAnd you trust openssl to not have a backdoor or flaw because?