This PR sets the default AESCrypt stream format to v2.
This is done to introduce the ability to read the v3 format before switching to the new format. With a delayed activation, it is more likely that users can easily roll back a version if needed.
This PR updates SharpAESCrypt to version 3.0.0.
With this change the written format for encrypted fields in the database and the remote encrypted files will be changed to Stream Format v3, which improves the key deriviation function and includes additional safeguards regarding content length.
The library still supports reading v2 files, but will write all new files as v3.
Environment variables, as well as module options, can toggle this behavior.
# Environment variable overview
- `DUPLICATI__AES_VERSION`: The file format version, either 3 (default) or 2
-`DUPLICATI__AES_V3_ITERATIONS`: The number of Pbkdf iterations to apply (default 300k)
- `DUPLICATI__AES_MINIMAL_HEADER`: Writes AES files with a minimal header (saves ~100 bytes per file)
- `DUPLICATI__AES_IGNORE_PADDING_BYTES`: Legacy setting for reading files written by the mainline AESCrypt tool
# A note on iterations
The iterations protect a weak key by adding additional computational overhead, but only adds overhead if the key is already providing at least 256 bits of high entropy.
For low-power devices, such as 32-bit RPI, this can be set as low as 10k, which will lower encryption and decryption time. Beware that setting a low iteration count reduces security if the key is not sufficiently strong.
- no code changes except those noted below
- projects upgrade to 4.6.2
- wixinstaller project upgraded automatically by VisualStudio
- wixinstaller updated to require 4.6.2
- Library.Encryption changed to Standard2.0 so accommodate update to SharpAesCrypt
Status: Fixed
I have now removed the code required to activate the deprecated AES crypt encryption, but kept the code required to decode it,
git-svn-id: https://duplicati.googlecode.com/svn/trunk@670 59da171f-624f-0410-aa54-27559c288bec
This was based on the idea that the interfaces should remain static.
I hope this change is enough to ensure stable interfaces until release 1.2.
Overview of changes:
Moved all interfaces into the same dll.
Encryption and compression is now plugable modules, just as the backends.
Encryption/compression can now register an UI.
Encryption now uses AESCrypt as a default.
GPG does not default to using the --armor option.
Added support for generic modules, but none are written yet.
Added support for plugable settings pages in the "Options" dialog.
Fixed issue #148.
Duplicati now uses AESCrypt as the default encryption format.
Fixed issue #199.
GPG now supports custom commandline options.
Fixed issue #207.
Encryption modules are now plugable.
Fixed issue #118.
S3 credentials are now stored.
Fixed issue #151.
Backends can now register system wide options.
git-svn-id: https://duplicati.googlecode.com/svn/trunk@427 59da171f-624f-0410-aa54-27559c288bec
Reworked encryption to not support streaming, but only pre/post process encrypted files.
The Get/Put methods in the BackendWrapper now automatically writes/reads from the signature cache.
Introduced a DoubleClickRadioButton for use on the main pages.
Fixed a bug where zero byte files would throw an exception on restore.
Fixed a bug where deleting a folder while building the filelist would interrupt the backup.
Fixed issue #17.
Fixed issue #22.
Fixed issue #38.
Added the commandline option to support issue #39, but still needs a UI entry.
git-svn-id: https://duplicati.googlecode.com/svn/trunk@131 59da171f-624f-0410-aa54-27559c288bec