‹ BackHN Continuity

Thread

Show HN: Air-gapped file encryption as self-decrypting HTML page

90 points · 31 comments · emurlin

  1. pwdisswordfishq · · focus · HN ↗
    I never expected to find a circumstance in which this article would be relevant, but here I am.

    <a href="https:&#x2F;&#x2F;jdebp.uk&#x2F;FGA&#x2F;dont-use-self-decrypting-files.html" rel="nofollow">https:&#x2F;&#x2F;jdebp.uk&#x2F;FGA&#x2F;dont-use-self-decrypting-files.html

    I mean, basing this on HTML arguably mitigates the portability and vulnerability concerns, but the problem of trusting the decrypted contents still remains.

    1. Hacker_Yogi · · focus · HN ↗
      Good to know. Thank you for sharing this!
    2. emurlin · · focus · HN ↗
      Good article, thanks for sharing! I agree with the claims it makes _and_ the reasoning behind them.

      This was motivated for situations where using GPG just isn&#x27;t practical. The issue is that there are very limited options to share a file securely without needing to install additional software (ZIP files come close to this, with some important caveats).

      As I was making this, I tried to mitigate many of the concerns raised in that article. For example:

      &gt; ask for an file that can be decrypted with an ordinary standalone decryption tool

      You don&#x27;t need to run the self-decryption code at all. You can use &#x27;ordinary&#x27; tools like `openssl` to decrypt the contents (note to self, add the `openssl` instructions to the `&lt;noscript&gt;` rendering).

      &gt; People who publish decryption tools expend effort to ensure that recipients can trust the actual decryption tools themselves before running them.

      You _can_ verify the integrity of the tool itself using gpg. Since you can&#x27;t verify the entire HTML file (otherwise, you wouldn&#x27;t be able to inject the encrypted payload), there&#x27;s ways a malicious actor could add additional scripts and still pass the integrity check. However, if you&#x27;re diligent enough to be using gpg to check this, you&#x27;d likely also be diligent enough to spot such additions, or you&#x27;d be using the openssl route.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.