‹ BackHN Continuity

Thread

Show HN: Air-gapped file encryption as self-decrypting HTML page

90 points · 31 comments · emurlin

  1. thih9 · · focus · HN ↗
    Is there a scenario where this solution would be preferable to an encrypted zip archive?

    My guess is some heavily locked down systems. But perhaps there is more?

    1. emurlin · · focus · HN ↗
      Author here. For the main use case that motivated my building this (securely sharing sensitive-ish data with non-technical people), yes, a ZIP file may have been preferable. That is what I was using before making this.

      ZIP files can use two types of encryption, ZipCrypto or AES. As the sibling comment points out, ZipCrypto is pretty broken. IIRC the AES encryption is OK or mostly OK, but it's not universally supported, so your recipient may or may not be able to open the file you send them. Notably, the Windows built-in ZIP implementation didn't support ZipCrypto (this may have changed now that Windows ships with bsdtar / libarchive).

      Subjectively, I feel this can be simpler to use (mostly for the recipient). You can host it at some server, share the link and the password and the recipient can access it like a regular website and get a plaintext download file. Compare that with a ZIP file, which with the same flow give you a ZIP download: if they don't immediately extract it, then they may have to hunt for the password later.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.