Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions Changelog.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,20 @@
> History prior to the ZeeCrypt fork belongs to the original [Picocrypt](https://github.com/Picocrypt/Picocrypt) project. New entries for ZeeCrypt will be added above this note going forward.

# v1.52 (Unreleased)
<ul>
<li>✓ Security: the header HMAC subkey is now derived after the keyfile key is mixed in. Previously a keyfile-only volume's header HMAC depended only on an empty password, so anyone could tamper with its header and recompute a valid HMAC. Because the data MAC doesn't cover the nonce, a tampered nonce then decrypted "successfully" to garbage. This is a breaking change for keyfile volumes only: decrypt keyfile volumes made with v1.50/v1.51 using v1.51, then re-encrypt. Password-only volumes are unaffected.</li>
<li>✓ Security: a failed decryption (damaged or modified data) now deletes the partially decrypted <code>.incomplete</code> file. Previously it was left on disk with unauthenticated plaintext, and the file chosen for overwriting was deleted instead.</li>
<li>✓ Security: a failed or cancelled decryption of a deniable volume no longer leaves the unwrapped <code>.tmp</code> file (which has a readable header) next to the volume.</li>
<li>✓ Fixed: the Reed-Solomon repair pass crashed on deniable volumes and always failed on split volumes. It now reuses the already recombined/unwrapped input.</li>
<li>✓ Fixed: crashes when decrypting a Reed-Solomon volume with a corrupted final padding byte or a truncated/appended tail, and when a file too short to be a volume is treated as deniable.</li>
<li>✓ Fixed: cancelling or running out of space while splitting now removes the partial <code>.incomplete</code> chunks.</li>
<li>✓ Fixed: the update prompt no longer opens over a running operation, and "Update Now" can't exit while one is in progress.</li>
<li>✓ Fixed: decrypting a deniable volume that needs keyfiles without selecting any shows a message instead of crashing.</li>
<li>✓ Fixed: pressing Enter during an operation could start a second one on the same files at the same time.</li>
<li>✓ Fixed: an existing file with the name of a temporary file (<code>*.tmp</code>) is no longer overwritten or deleted; you're asked to remove it instead. Cleanup only ever deletes files the app created itself.</li>
<li>✓ Fixed: splitting a file whose name contains <code>[</code>, <code>*</code> or <code>?</code> deleted the volume and left its chunks unusable.</li>
</ul>

# v1.51 (Released 08/02/2026)
<ul>
<li>✓ Added Explorer right-click integration: a single "Open with ZeeCrypt" entry for files and folders. The app already auto-detects encrypt vs. decrypt from what's opened, so there's no separate Encrypt/Decrypt entry to guess wrong. Multi-select launches one instance with every selected path passed along.</li>
Expand Down
4 changes: 3 additions & 1 deletion Internals.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,13 +29,15 @@ A ZeeCrypt volume's header is encoded with Reed-Solomon by default since it is,
| 93+3C | 96 | 32 | Salt for HKDF-SHA3
| 189+3C | 48 | 16 | IV for Serpent
| 237+3C | 72 | 24 | Nonce for XChaCha20
| 309+3C | 192 | 64 | HMAC-SHA3-512 of the header (flags, salts, IVs), keyed by a subkey derived from the password
| 309+3C | 192 | 64 | HMAC-SHA3-512 of the header (flags, salts, IVs), keyed by a subkey derived from the password and keyfiles
| 501+3C | 96 | 32 | SHA3-256 of keyfile key
| 597+3C | 192 | 64 | Authentication tag (BLAKE2b/HMAC-SHA3)
| 789+3C | | | Encrypted contents of input data

As of v1.50, this header HMAC replaces a bare SHA3-512 hash of the encryption key. Verifying it before any data is processed both detects an incorrect password and detects tampering with the header's decryption parameters (flags, salts, IVs) — closing findings PCC-001 and PCC-006 from the original Picocrypt security audit (Radically Open Security, September 2024). The comment field is deliberately excluded from this HMAC (see the in-app tooltip: comments are neither encrypted nor tamper-protected). This is a breaking format change — ZeeCrypt v1.50 cannot open volumes created by Picocrypt or by ZeeCrypt versions prior to 1.50.

As of v1.52, the header HMAC subkey is derived (HKDF-SHA3, info `zeecrypt-header-mac`) from the final encryption key, i.e. after the Argon2 output has been XORed with the keyfile key. In v1.50–1.51 it was derived before that XOR, so for a keyfile-only volume (empty password) the subkey depended only on `argon2id("", salt)` — computable from the header alone — and anyone could rewrite the header parameters and recompute a valid HMAC. Because the data MAC authenticates the ciphertext but not the nonce/IV, a rewritten nonce then decrypted "successfully" to garbage. This is another breaking change, but only for volumes that use keyfiles: keyfile volumes made with v1.50 or v1.51 must be decrypted with v1.51 and re-encrypted. Password-only volumes are unaffected.

# Keyfile Design
ZeeCrypt allows the use of keyfiles as an additional form of authentication. ZeeCrypt's unique "Require correct order" feature enforces the user to drop keyfiles into the window in the same order as they did when encrypting in order to decrypt the volume successfully. Here's how it works:

Expand Down
2 changes: 1 addition & 1 deletion VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.51
1.52
2 changes: 1 addition & 1 deletion dist/windows/installer.wxs
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
before running this in a shell:
dotnet tool install ‑‑global wix ‑‑version 5.0.2
wix extension add WixToolset.UI.wixext/5.0.2
wix build dist/windows/installer.wxs -arch x64 -ext WixToolset.UI.wixext -d ExePath=src/ZeeCrypt.exe -d IconPath=images/lock.ico -d LicenseRtfPath=dist/windows/License.rtf -d ProductVersion=1.51.0.0 -o ZeeCrypt-Installer.msi
wix build dist/windows/installer.wxs -arch x64 -ext WixToolset.UI.wixext -d ExePath=src/ZeeCrypt.exe -d IconPath=images/lock.ico -d LicenseRtfPath=dist/windows/License.rtf -d ProductVersion=1.52.0.0 -o ZeeCrypt-Installer.msi

Pinned to WiX v5: v7 introduced a mandatory "Open Source Maintenance Fee"
EULA that must be accepted before the tool will run at all. Don't bump
Expand Down
3 changes: 3 additions & 0 deletions src/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,9 @@ Note: Make sure to set `CGO_ENABLED=1` if it isn't already. Also make sure **not
# 5. Done!
You should now see a compiled executable (`ZeeCrypt.exe`) in your directory, with the app icon already embedded. You can run it by double-clicking or executing it in your terminal. That wasn't too hard, right? Enjoy!

# Running the tests
<code>go test .</code> (with `CGO_ENABLED=1`) runs headless end-to-end tests that drive the same code paths as the UI: round trips across every option, tampering/corruption and Reed-Solomon repair, cleanup of temporary files on failure, and compatibility with the v1.51 volumes in `testdata/`. Each encryption or decryption runs Argon2id with 1 GiB of memory, so the suite takes about a minute and needs a few GiB of free RAM.

# Updating the app icon
The icon is embedded automatically via `rsrc_windows_386.syso`/`rsrc_windows_amd64.syso` in this directory, which `go build` links in without any extra flags. If you change `images/lock.ico`, regenerate these files:
```
Expand Down
Loading
Loading