Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #204281

Re: Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files

From Ben Caradoc-Davies <ben@transient.nz>
Newsgroups linux.debian.user
Subject Re: Looking for advice on tools (or libraries) for unsupervised, bulk symmetric encryption/decryption of files
Date 2019-01-10 06:10 +0100
Message-ID <xeALo-3qW-5@gated-at.bofh.it> (permalink)
References <xemIp-3aB-15@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 10/01/2019 03:05, Kynn Jones wrote:
> The only encryption tool I have used for encrypting files on my hard drive
> is gpg2, which I have used for small, interactive encryption tasks
> (half-dozen files, at most).
> Therefore, my initial attempt was to use gpg2 for this new bulk-encryption
> task, but I found myself constantly fighting with it, and finally had to
> recognize that I was trying to use gpg2 for something it is not primarily
> designed for.  (I am also a bit concerned with gpg2's future stability.
> AFAICT, It's design has varied significantly over the years, and as a
> result there's a lot of confusion on its use.  That has been my experience,
> in any case.)

I use a pipe with gpg2 as one component for symmetric encryption:

gpg --batch --symmetric --cipher-algo AES256 --s2k-digest-algo SHA512 
--compress-algo none --passphrase-file $PASSPHRASE_FILE

My pipe input is usually a tar file gzipped with pigz for parallel 
compression, hence the "--compress-algo none". I then add another "pigz 
-0" wrapper to get a cryptographically weak checksum to allow testing 
for media failures without the passphrase. I like tar because it 
preserves file metadata and filesystem structure and is a very stable 
format. Other formats may be better for random access.

Recently I used gpg2 to decrypt files that were encrypted over 15 years 
ago; note that these were much smaller files and a simpler invocation of 
gpg1 (the then default cipher was CAST5 IIRC). The gpg file format seems 
well-documented and stable. Regular decryption tests are prudent to 
catch problems after gpg upgrade. Yes, the new interactive predilections 
of gpg2 were a pain at first when compared to gpg1, but "--batch" and 
"--passphrase-file" seem sufficient for batch symmetric encryption, if 
you do not mind your passphrase being in plain text on your filesystem.

Kind regards,

-- 
Ben Caradoc-Davies <ben@transient.nz>
Director
Transient Software Limited <https://transient.nz/>
New Zealand

Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Looking for advice on tools (or libraries) for unsupervised, bulk  symmetric encryption/decryption of files Kynn Jones <kynnjo@gmail.com> - 2019-01-09 15:10 +0100
  Re: Looking for advice on tools (or libraries) for unsupervised, bulk  symmetric encryption/decryption of files David Christensen <dpchrist@holgerdanske.com> - 2019-01-09 20:00 +0100
  Re: Looking for advice on tools (or libraries) for unsupervised,          bulk symmetric encryption/decryption of files Linux-Fan <Ma_Sys.ma@web.de> - 2019-01-10 00:50 +0100
  Re: Looking for advice on tools (or libraries) for unsupervised,  bulk symmetric encryption/decryption of files Celejar <celejar@gmail.com> - 2019-01-10 04:20 +0100
    Re: Looking for advice on tools (or libraries) for unsupervised,  bulk symmetric encryption/decryption of files Jonathan Dowland <jmtd@debian.org> - 2019-01-11 22:50 +0100
      Re: Looking for advice on tools (or libraries) for unsupervised,  bulk symmetric encryption/decryption of files Celejar <celejar@gmail.com> - 2019-01-13 04:50 +0100
        Re: Looking for advice on tools (or libraries) for unsupervised, bulk  symmetric encryption/decryption of files John Crawley <john@bunsenlabs.org> - 2019-01-13 10:00 +0100
  Re: Looking for advice on tools (or libraries) for unsupervised, bulk  symmetric encryption/decryption of files Ben Caradoc-Davies <ben@transient.nz> - 2019-01-10 06:10 +0100

csiph-web