Encrypting files for yourself
Encrypting a file ensures that the contents cannot be read or modified without the secret key. This is useful for protecting your files on external storage (e.g. memory sticks) or in the cloud.
Using a passphrase
Kryptor will convert your passphrase into a unique encryption key per file/directory. For security reasons, this involves a slight delay.
To prevent the file from being decrypted by someone else, always use a strong passphrase!
If you forget your passphrase, any files encrypted using that passphrase will be unrecoverable. Therefore, using a password manager is strongly recommended.
You can either type your passphrase:
Interactively (recommended): you'll be asked to enter a new passphrase and then to retype the passphrase for confirmation. You can type nothing initially to randomly generate a passphrase. The characters you type are hidden to prevent someone from seeing your passphrase and the length of the passphrase.
Non-interactively (less secure): this involves specifying the passphrase on the command line. You can type
" "
to randomly generate a passphrase.
Here's an example using interactive passphrase entry:
Here's an example using non-interactive passphrase entry:
Using a symmetric key
Kryptor will convert the specified or randomly generated symmetric key into a unique encryption key per file/directory. Unlike using a passphrase, this involves no delay.
If you lose the symmetric key, any files encrypted using that symmetric key will be unrecoverable. Therefore, using a password manager is strongly recommended.
Here's an example of randomly generating a symmetric key string:
Here's an example of using the same symmetric key string again:
Using a keyfile
Kryptor will convert the hash of the keyfile into a unique encryption key per file/directory. Keyfiles can be used alongside (recommended) or instead of a passphrase (less secure).
When used with a passphrase, the keyfile is like 2FA. Used alone, it's weaker than a passphrase in that it's stored on disk and cannot be memorised.
If the keyfile is lost or modified, files encrypted using that keyfile will become unrecoverable. Therefore, you should back up keyfiles to external storage (e.g. memory sticks).
Never share a keyfile! Keep them secret and offline!
You can either:
Randomly generate keyfiles (recommended): you can specify a non-existent file to give the keyfile a name, or you can specify a directory that exists to generate a keyfile with a random name.
Select ordinary files (less secure): you can specify any file that's at least 32 bytes long. Compressed files (e.g.
.zip
) are strongly recommended.
Here's an example of randomly generating a keyfile alongside using a passphrase:
Here's an example of using an ordinary file as a keyfile alongside a passphrase:
Using a private key
Kryptor will convert your encryption private key into a unique encryption key per file/directory.
This requires an encryption key pair, which can be generated as follows:
Or non-interactively like so:
If you lose the private key file, files encrypted using that private key will be unrecoverable. Therefore, you should back up the private key file to external storage (e.g. memory sticks).
Never share your private key file! Keep it secret and offline!
When performing encryption, you'll be asked to decrypt your private key using your passphrase. For security reasons, this involves a slight delay.
Here's an example of how to use your default encryption private key:
Here's an example of how to specify an encryption private key not stored in the default folder:
Last updated