Simple Password Encrypted Files w/ GnuPG
runtime-era.blogspot.com
runtime-era.blogspot.com
It uses GPG for symmetric encryption as per TFA.
I like that.
(Non-security-researcher suggestion follows, take with a grain of salt): Note that the default encryption algo used with the -c option is usually CAST5. Though there haven't been any successful attacks against it yet, in today's world of the NSA storing communications indefinitely you might want to consider using AES256 instead of CAST5 to (semi) future-proof your encrypted files. You can do that by adding the following line to ~/.gnupg/gpg.conf:
personal-cipher-preferences aes256 3des
If I'm misguided in that suggestion please do let me know!In fact, we're interesting in open-sourcing it since it's really rough around the edges. If anyone is interested in working on it with us, hit me up and maybe we can toss it up on github and make it more nice together.
http://vim.wikia.com/wiki/Edit_gpg_encrypted_files
If you structure the file, say, passswords, appropriately, or even very loosely (one record per line), you can write a bash script or function to query the file. More useful if you've got a pgp-agent running. Say:
qpass () { gpg -d ~/passwords.asc | grep $1; }
... and when you want to know your HN password, you query it with 'qpass ycomb'http://www.arg0.net/encfsintro
To me it fits better with "The UNIX Way" - works with all the other tools and so on. Doing it in vim is probably more portable, though :/
http://emacs-fu.blogspot.com/2011/02/keeping-your-secrets-se...
I.e. Bob encrypted a bunch of critical files and left the company. While I don't want someone that hacks into the server to be able to decrypt them (so the key must be kept in a separate location, like Bob's head) I do want to make sure I can decrypt the files under those special circumstances, but they have to be stored in a way that makes them hard to get.
As a technical solution for encrypting data, GPG is peachy.
When the VA had a laptop theft that resulted in a large identity breach, many government entities freaked and implemented policies that they didn't understand. Think schools, local government, etc.
In these situations, you may find yourself in trouble when auditors catch a security issue violating your own policy, because dog licensure data isn't properly encrypted.