Air-gapped file encryption packed into a single, self-decrypting HTML page. Repo: https://github.com/ApelegHQ/ts-cms-ep-sfx I was inspired by self-extracting archives. I wanted to share files with…

90 points•emurlin•7 days ago•32 comments•
Air-gapped file encryption packed into a single, self-decrypting HTML page. Repo: https://github.com/ApelegHQ/ts-cms-ep-sfx

I was inspired by self-extracting archives. I wanted to share files with basically no dependencies. The goal was:

  1. Something that didn't require any installation (assuming a web browser)
  2. Have a single file with no network that could self-decrypt
  3. Be fully auditable
The second point is done by having (sort of(*)) reproducible builds and embedded OpenPGP signatures.

The first point is made by cleverly manipulating the HTML structure so that it can decrypt without breaking the PGP signature. It can even decrypt using bare openssl (which was a design goal too, though getting the exact structure right took some work and bug reports).

The third point is accomplished by the first two, and by the source being freely available.

(*) Depends on the OS at the moment.

32 comments

technion6 days ago
I never thought I'd see a browser support list that specifically includes "Dilo" or, in the last few years, "Internet Explorer", but apparently you're comprehensive.

I went to look for unauthenticated CBC mode like every time I see this sort of thing but it's actually GCM mode so, well consider me surprised.

black_knight6 days ago
It does say Dillo is unsupported, though! Which is a shame. No mention of Mothra…
calvinmorrison6 days ago
Mothra intentionally does not support this
lukan6 days ago
I assume the "air gapped" part is merely indicating no internet required?
az2266 days ago
Offline would be a better word.
som6 days ago
A version of this that supported PKE would be cool. So you don't have to share a password in a side channel
itake6 days ago
I built something similar, but mine used asymetric encryption.

It allowed people encrypt files and then the only person that can decrypt is the person with the private key, which may or may not be the person the encrypted the file.

mprime16 days ago
Came up with something similar a for myself: https://mprimi.github.io/portable-secret/ it was well liked by HN: https://news.ycombinator.com/item?id=34083366

Read the full thread on Hacker News →

Related stories