Cryptex 2.0.0
dotnet tool install --global Cryptex --version 2.0.0
dotnet new tool-manifest
dotnet tool install --local Cryptex --version 2.0.0
#tool dotnet:?package=Cryptex&version=2.0.0
nuke :add-package Cryptex --version 2.0.0
Cryptex
A free command-line tool for encrypting and decrypting files and folders with a passphrase, using AES-256-GCM authenticated encryption.
No warranty. Cryptex is free software provided "as is". Booolean (booolean.com) and the contributors accept no responsibility or liability for any data loss or other damage arising from its use.
Installation
Requires the .NET 10 runtime or SDK.
dotnet tool install -g Cryptex
Usage
cryptex encrypt <inputFile> <outputFile> [options] (alias: e)
cryptex decrypt <inputFile> <outputFile> [options] (alias: d)
cryptex encrypt-folder <folderPath> [options] (alias: ef)
cryptex decrypt-folder <folderPath> [options] (alias: df)
Options:
-p, --passphrase <pass> Passphrase (visible in shell history and to other processes)
-x, --delete-original Delete source files after successful encryption
-h, --help Show help
-v, --version Show the version
cryptex encrypt report.pdf report.pdf.enc
cryptex decrypt report.pdf.enc report.pdf
cryptex encrypt-folder ./confidential
cryptex decrypt-folder ./confidential
encrypt-folder writes <name>.enc next to every file in the folder tree. decrypt-folder decrypts every .enc file to the same name without .enc and keeps the encrypted files.
Passphrase
Taken from the first of these that is set:
--passphrase/-p(use with caution)- The
CRYPTEX_PASSPHRASEenvironment variable (recommended for scripts) - An interactive prompt with hidden input
Things to know
- Existing output files are overwritten without asking.
- A lost passphrase cannot be recovered.
- Markdown files (
.md,.markdown) are never encrypted or decrypted. - Symbolic links are skipped by folder commands.
--delete-originalis a normal delete, not a secure erase.- File names, sizes and folder structure are not hidden.
Configuration (.cryptex.yaml)
Read from the current working directory on every run:
# Delete each plaintext source after it has been encrypted successfully. Default: false.
deleteOriginalOnEncrypt: true
# Glob patterns, relative to the folder being processed, to skip in folder commands.
exclude:
- "*.log" # any depth
- ".env" # any depth
- "secrets/**" # everything below secrets
An invalid .cryptex.yaml stops Cryptex before any file is touched.
Security details
- Cipher: AES-256-GCM with a 16-byte tag, in 64 KiB chunks; tampering, truncation and reordering are detected
- Key derivation: PBKDF2-HMAC-SHA256 with 600,000 iterations and a random salt, then HKDF-SHA256 with a random per-file salt
- Atomic output: files appear at their final path only when complete and authenticated
Cryptex 2 reads files written by Cryptex 1.x. Files written by Cryptex 2 cannot be read by Cryptex 1.x.
Full documentation: https://github.com/greatb/Cryptex
Disclaimer
Cryptex is free of charge and provided "as is", without warranty of any kind. To the fullest extent permitted by law, Booolean (booolean.com), the owner and the contributors are not responsible or liable for any loss of data or any other damage that results from, or is suspected to result from, using Cryptex. You use it at your own risk. Keep independent backups.
License
MIT
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.