Skip to content

ZeeCrypt v1.50: Windows-only rebrand + Picocrypt security audit fixes - #1

Merged
TheZeekA merged 6 commits into
mainfrom
testing
Aug 1, 2026
Merged

TheZeekA merged 6 commits into
mainfrom
testing

Conversation

@TheZeekA

@TheZeekA TheZeekA commented Aug 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Forked from Picocrypt and rebranded to ZeeCrypt: renamed source, module, window title, packaging metadata, and docs; removed macOS/Linux/Flatpak/Snapcraft support and CI since this fork only targets Windows.
  • New visual identity: light theme (replacing giu's default dark theme), new app icon (embedded automatically via go-winres), new logo, updated README screenshot.
  • v1.50: fixes 4 of the 6 findings from the original Picocrypt security audit (Radically Open Security, Sept 2024):
    • PCC-001 / PCC-006 — replaced the header's bare SHA3-512 hash of the encryption key with an HMAC-SHA3-512 of the header (flags, salts, IVs), keyed by an independent password-derived subkey. Authenticates the header against tampering in addition to verifying the password.
    • PCC-002 — fixed a crash when previewing a dropped file with a corrupted/tampered negative comment-length field.
    • PCC-005 — an over-length comment now aborts cleanly with a status message instead of crashing the app.
    • PCC-003 was already fixed upstream before this fork (RNG errors are checked).
    • PCC-004 (decrypt-then-verify) is documented as a known, low-severity limitation in Internals.md rather than fixed — a proper fix touches the Reed-Solomon repair path, deniability temp-zip wrapper, and split/recombine handling all at once, too risky to rewrite blind without a way to compile/test it.

Breaking changes

  • The header-authentication format change means v1.50 cannot decrypt volumes created by Picocrypt or earlier ZeeCrypt builds. This was a deliberate choice (clean break, no legacy-format fallback) given ZeeCrypt has no existing user base yet.

Test plan

  • Build succeeds (go build . from src/, not naming ZeeCrypt.go directly — needed for the icon to embed)
  • Encrypt → decrypt round-trip: normal mode
  • Encrypt → decrypt round-trip: paranoid mode
  • Encrypt → decrypt round-trip: keyfiles (ordered and unordered)
  • Encrypt → decrypt round-trip: deniability
  • Encrypt → decrypt round-trip: Reed-Solomon
  • Encrypt → decrypt round-trip: split/recombine
  • Wrong password on decrypt shows "incorrect, or the file has been tampered with"
  • App icon and light theme render correctly

TheZeekA and others added 6 commits August 2, 2026 08:31
Renames all Picocrypt references to ZeeCrypt across source, docs, and
Windows packaging metadata. Drops macOS/Linux/Flatpak/Snapcraft
packaging and CI workflows since this fork only targets Windows.
External Picocrypt-hosted Go dependencies (github.com/Picocrypt/*) are
left untouched since they are real upstream packages, and attribution
to the original Picocrypt project is preserved in the README and
source header per GPL-3.0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Use images/lock.ico for the Windows app icon (MAINICON/GLFW_ICON) in
place of key.ico, and images/zeecrypt-logo-scaled.png for the README
logo. Removes the old key.ico, key.svg, logo.svg, and zeecrypt-logo.png
now that nothing references them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Override giu's hardcoded dark theme with a light palette (window/frame
backgrounds, text, and accent colors), and retune the RED/GREEN/YELLOW
status-text colors for contrast against a light background (the old
neutral WHITE status color is renamed NEUTRAL and set near-black).

Embed images/lock.ico into the Windows build via go-winres, generating
rsrc_windows_386.syso/rsrc_windows_amd64.syso which go build links in
automatically. Fix the build commands in src/README.md and both
Windows CI workflows to build the package directory (`.`) instead of
naming ZeeCrypt.go explicitly, since Go only auto-links .syso resource
files in directory-based builds.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The old screenshot was still showing Picocrypt's dark theme.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…s from the Picocrypt security audit

- PCC-001/PCC-006: replace the header's stored SHA3-512 hash of the
  encryption key with an HMAC-SHA3-512 of the header (flags, salts, IVs),
  keyed by an independent password-derived subkey. This authenticates the
  header against tampering in addition to verifying the password. Breaking
  format change: v1.50 cannot open volumes from Picocrypt or earlier
  ZeeCrypt versions.
- PCC-002: fix a crash when previewing a dropped file whose comment-length
  field was corrupted/tampered to a negative value; the file-drop preview
  path now validates the length field the same way the decrypt path does.
- PCC-005: encrypting with a comment over 99,999 characters now aborts
  cleanly with a status message instead of panicking.
- PCC-003 was already fixed upstream (RNG errors are checked). PCC-004
  (decrypt-then-verify) remains open for a future release; see Internals.md
  for why and what already mitigates it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant