Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #204281
| From | Ben Caradoc-Davies <ben@transient.nz> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files |
| Date | 2019-01-10 06:10 +0100 |
| Message-ID | <xeALo-3qW-5@gated-at.bofh.it> (permalink) |
| References | <xemIp-3aB-15@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 10/01/2019 03:05, Kynn Jones wrote: > The only encryption tool I have used for encrypting files on my hard drive > is gpg2, which I have used for small, interactive encryption tasks > (half-dozen files, at most). > Therefore, my initial attempt was to use gpg2 for this new bulk-encryption > task, but I found myself constantly fighting with it, and finally had to > recognize that I was trying to use gpg2 for something it is not primarily > designed for. (I am also a bit concerned with gpg2's future stability. > AFAICT, It's design has varied significantly over the years, and as a > result there's a lot of confusion on its use. That has been my experience, > in any case.) I use a pipe with gpg2 as one component for symmetric encryption: gpg --batch --symmetric --cipher-algo AES256 --s2k-digest-algo SHA512 --compress-algo none --passphrase-file $PASSPHRASE_FILE My pipe input is usually a tar file gzipped with pigz for parallel compression, hence the "--compress-algo none". I then add another "pigz -0" wrapper to get a cryptographically weak checksum to allow testing for media failures without the passphrase. I like tar because it preserves file metadata and filesystem structure and is a very stable format. Other formats may be better for random access. Recently I used gpg2 to decrypt files that were encrypted over 15 years ago; note that these were much smaller files and a simpler invocation of gpg1 (the then default cipher was CAST5 IIRC). The gpg file format seems well-documented and stable. Regular decryption tests are prudent to catch problems after gpg upgrade. Yes, the new interactive predilections of gpg2 were a pain at first when compared to gpg1, but "--batch" and "--passphrase-file" seem sufficient for batch symmetric encryption, if you do not mind your passphrase being in plain text on your filesystem. Kind regards, -- Ben Caradoc-Davies <ben@transient.nz> Director Transient Software Limited <https://transient.nz/> New Zealand
Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread
Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files Kynn Jones <kynnjo@gmail.com> - 2019-01-09 15:10 +0100
Re: Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files David Christensen <dpchrist@holgerdanske.com> - 2019-01-09 20:00 +0100
Re: Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files Linux-Fan <Ma_Sys.ma@web.de> - 2019-01-10 00:50 +0100
Re: Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files Celejar <celejar@gmail.com> - 2019-01-10 04:20 +0100
Re: Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files Jonathan Dowland <jmtd@debian.org> - 2019-01-11 22:50 +0100
Re: Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files Celejar <celejar@gmail.com> - 2019-01-13 04:50 +0100
Re: Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files John Crawley <john@bunsenlabs.org> - 2019-01-13 10:00 +0100
Re: Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files Ben Caradoc-Davies <ben@transient.nz> - 2019-01-10 06:10 +0100
csiph-web