Show HN: Shell utility to encrypt a file into a self-decrypting script
github.com
github.com
Of course you could inspect the file, but that's extra work which many people won't bother with.
I guess what's really needed is a simple encrypted format that's easy to decrypt without needing to worry about command line arguments. For example, people are generally satisfied with .tar.* formats and not looking for self extracting compressed formats.
I have to google the extract arguments for tar every single time I use it. What was it again, -xfv?
-xvf is sufficient even if the archive is compressed
The dash is optional as well. tar xvf archive.tar.gz works just fine.
tar -xf archive.tar # Extract all files from archive.tar.
If you work with lots of different types of archives or have a hard time remembering the various tools and arguments, I recommend dtrx (Do The Right Extraction). Super simple and it ensures you don't accidentally dump a whole directory tree somewhere it shouldn't. Assuming you have pip and hg installed, you can install the latest version to your user site with the following command: pip2 install --user hg+http://www.brettcsmith.org/2007/dtrx/dtrx
Then all you have to remember is `dtrx ARCHIVE...`https://github.com/psypete/public-bin/blob/public-bin/src/sy...
So it still requires either storing that new secret (the password) somewhere (which defeats the purpose of using this technique to guard your secrets), or you need a human (which defeats the purpose of automated deployments).
.. and that signature can't really be verified by unverified code.