Encryption

The quiet success of Autocrypt and Deltachat

PGP has been around for about 35 years, more or less, and the single reason emails are rarely OpenPGP-encrypted is most people don’t know how to use OpenPGP. To get it right, we need to know what asymmetric encryption is, which algorithms and key sizes to use, how to include the correct key in our email signatures and how to make backups of our private keys. OpenPGP requires effort to use, and most of us invariably choose convenience over security.

Upgrading LUKS Key Derivation Function

While everything in a Tails OS session is wiped from system memory after the laptop is switched off, the option to store data persistently in an encrypted partition (the Persistent Storage) is a critical feature for users, such as journalists, who, for example, need to create notes, save material and draft reports during a session. The encryption used for this - LUKS - is the standard for disk and volume encryption in Linux.

Encrypting the Joplin Database

Though Joplin comes with end-to-end encryption, that feature only protects the data stored on whichever server is being used for syncing the notes between applications. On standard installations, the data isn’t actually encrypted locally on the devices themselves, the way it is with Standard Notes. In Windows, the notes are stored in an SQLite file in C:\Users[User Name].config\joplin-desktop. Opening the database file using an SQLite browser, we can see the notes and password-derived cryptographic keys are actually stored unencrypted.

Vim Document Encryption

It is possible to save the content of a Vim session as an encrypted file, simply by using the ‘:X’ command and setting a password. The problem is the default encryption mode is considered weak - PkZip is a stream cipher that XORs the password with the file content, and the first Blowfish implementation for Vim can have repeating bytes in the ciphertext (see ‘:help cryptmethod’). Using the default mode, we get the following message: