3 ms·
Another similar project that aims to do the same thing: https://github.com/elasticdog/transcrypt https://github.com/elasticdog/transcrypt The readme contains a
by roller 13y ago
Another similar project that aims to do the same thing:
https://github.com/elasticdog/transcrypt https://github.com/elasticdog/transcrypt
The readme contains an itemized comparison, though it sounds some of this actual comparison may be out of date or more specific to git-encrypt (yet another project) git-crypt does appear to use openssl libraries for example.
transcrypt is just a Bash script and does not require compilation
transcrypt uses OpenSSL's symmetric cipher routines rather then implementing its own crypto
transcrypt does not have to remain installed after the initial repository configuration
transcrypt generates a unique salt for each encrypted file
transcrypt uses safety checks to avoid clobbering or duplicating configuration data
transcrypt facilitates setting up additional clones as well as rekeying
transcrypt adds an alias git ls-crypt to list all encrypted files
- agwa 13y agoCool, thanks for pointing me towards transcrypt - I hadn't heard of it until now. You are correct: git-crypt does use the OpenSSL libraries; we do not roll our own crypto. I'm happy to see transcrypt didn't make the most common crypto mistake that Git crypto projects made, which is to use a block cipher in ECB mode or CBC mode with a fixed IV. That said, I don't think it's a good idea to implement this with shell scripts. While shell scripts are extremely convenient, it's very hard to write them securely. For example, in one place transcrypt leaks your passphrase as an argument to an openssl command, meaning there's an instant where another user could see it in the output of `ps`.