4 ms·
> openssl enc Careful. Openssl enc is basically a poor toy example, it's not a robust authenticated encryption tool for real world use. It explicitly doesn't
by Freaky 11y ago
> openssl enc
Careful. Openssl enc is basically a poor toy example, it's not a robust authenticated encryption tool for real world use.
It explicitly doesn't support modern AEAD ciphers or even a simple MAC (so the ciphertext can be silently tampered with - note anyone who can do that can also replace your par2 files), and it doesn't use a robust key derivation algorithm for password use (single-round of a hash, basically, default MD5 - about as weak as it comes).
hpenc looks like a nice high performance modern alternative: https://github.com/vstakhov/hpenc https://github.com/vstakhov/hpenc