age
git-crypt
Our great sponsors
age | git-crypt | |
---|---|---|
213 | 50 | |
15,264 | 7,964 | |
- | - | |
5.5 | 0.0 | |
about 1 month ago | 3 months ago | |
Go | C++ | |
BSD 3-clause "New" or "Revised" License | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
age
- Age: A simple, modern and secure encryption tool
-
Joining ChatCraft.org
and echoing the result after converting to an age private key
-
What is the point of a public key fingerprint?
I like that https://github.com/FiloSottile/age has small public keys.
-
OpenPGP Forked into "LibrePGP" by GnuPG's Maintainer Werner Koch
> something fresh
It exists, it's called age..
Some random links
https://github.com/FiloSottile/age
https://www.reddit.com/r/crypto/comments/hr64hr/state_of_age...
https://github.com/FiloSottile/age/discussions/432
> (Acquiring keys, rotating keys, identifying compromised keys, and most importantly either reaches a large enough percentage of emails..
Oh nevermind, age doesn't do any of that. Indeed, it doesn't even do email https://github.com/FiloSottile/age/issues/93
-
An opinionated template for deploying a single k3s cluster with Ansible backed by Flux, SOPS, GitHub Actions, Renovate, Cilium, Cloudflare and more!
Encrypted secrets thanks to SOPS and Age
-
Prettier $20k Bounty was Claimed
I never heard of "Age" before this post. Thank you to share. If others are interested to learn more, here are two other interesting posts about Age:
https://github.com/FiloSottile/age/discussions/432
https://words.filippo.io/dispatches/age-authentication/
-
Cosmopolitan Third Edition
of all things I was able to resolve the issue via this github issue: https://github.com/FiloSottile/age/issues/370#issuecomment-1...
-
Would you trust a repository made like this to save your secrets?
Why keep something secret on a public repo? Is that not an oxymoron?
Also, I’m terms of encryption something like age[0] makes it much easier to not shoot yourself in the foot.
[0] https://github.com/FiloSottile/age
-
Looking For Encryption App
Why RSA specifically? For backups, I recommend Tarsnap. But if you really don't want to pay for encrypted cloud hosting, then check out age encryption.
-
OpenSSL and a rookie (me)
I wouldn't use OpenSSL personally. If you just need simple but secure symmetric encryption, checkout the scrypt(1) encryption utility from Tarsnap. If you need support for public keys, check out age(1).
git-crypt
-
Why Can't My Mom Email Me?
https://github.com/AGWA/git-crypt
And occasionally to encrypt files, or receive encrypted files.
These are practical things which are non-theoretical.
> Using multiple keys don't offer added security or secrecy.
Depends on how careful you are or want to be, with your private key. My house key isn't the same as my car key isn't the same as my bike key.
> This is nothing like data harvesting
Alright fair, bad example. What I was grumbling about was more the lack of any clear communication that you've been auto-opted-in to a feature on protonmail, with no user interface signal indicating so, leading to confusion for a couple months like in TFA. I definitely wasn't casting shade on the opengpg keyserver, nor protonmail. It's the "hey! I didn't check a box for this, and it's not mentioned anywhere in the protonmail docs" hidden functionality which could do with some clarification.
I'm a forgetful creature. If I intentionally put my key on a keyserver, because I'm playing around and learning about PGP, will I make the connection between it and protonmail a few months down the line if I move my email account to them? Unlikely.
It's a nice automated feature. Protonmail-to-protonmail e2e encryption makes a lot of sense. I just think protonmail-to-non-protonmail e2e needs a tooltip in the UI, and the option to opt out, potentially with the ability to opt out for specific email addresses. I wouldn't at all assume it would be on by default even IF I've been actively using PGP in my email clients, because it's something you usually have to manually set up yourself, very explicitly. That, and 99.9% of emails are plaintext.
Anyhoo, one thing I forgot which kind of negates the "what if I have multiple encryption keys tied to my email" is the fact that the opengpg keyserver does tie 1 email address to 1 key so you can't publish multiple encryption keys, fair enough. Git-crypt and file encryption, I set my associated email address to use +tags eg [email protected], so as far as protonmail etc are concerned there's only one key per logical email address.
-
Is it safe to commit a Terraform file to GitHub?
Apart from a few exceptions (like ansible for example, which supports native encryption), we moved away from encrypted secrets in git repos and use external things, depending on the platform (like parameter store / secrets manager for AWS or keyvault for Azure - both of these do track changes, btw), so I haven't looked for quite a while. Back in ye olden days we used https://github.com/AGWA/git-crypt which worked quite nicely, but the key management is cumbersome and it's based on GPG, which in itself is a bit of a light redish flag these days.
-
GitHub Private Repos Considered Private-Ish
How about encryption?
https://github.com/AGWA/git-crypt has been solid for me
-
Codeship jet alternative
You might want to check out git-crypt. It allows you to encrypt and decrypt files in a git repo without needing an external account, and supports .env files. That said, trying your hand at making one as a personal project could be a fun and rewarding experience!
-
Ask HN: Privacy-Conscious GitHub?
I hesitate to append this but one option I have seen thrown around and also debated is git-crypt [1] There are many caveats to doing this as any integrations that would need to read the file contents would also need to be able to decrypt the files so this may not be entirely useful and may add many levels of complexity and fragility.
[1] - https://github.com/AGWA/git-crypt
-
Vaults vs. Cryptomator? Security, Cloud syncing, integration?
The most interesting approach I've seen for this is https://github.com/AGWA/git-crypt
-
How can I Make this binary statically-linked?
Here is the Makefile.
I use git-crypt to encrypt files in git repositories quite a lot and I find that it doesn't work on RHEL-based distros because of some missing or out-of-date library. I need to build a statically linked binary.
-
How to Deploy and Scale Strapi on a Kubernetes Cluster 1/2
Store the Secrets in a repo using gitcrypt or another encryption tool.
-
I moved all my input files to a private repo and used it as a submodule
Consider using git-crypt for transparent encryption instead.
What are some alternatives?
sops - Simple and flexible tool for managing secrets
git-secrets - Commit files with sensitive information like environment secrets safely encrypted in GitHub
Picocrypt - A very small, very simple, yet very secure encryption tool.
rage - A simple, secure and modern file encryption tool (and Rust library) with small explicit keys, no config options, and UNIX-style composability.
sealed-secrets - A Kubernetes controller and tool for one-way encrypted Secrets
age-plugin-yubikey - YubiKey plugin for age
dendron - The personal knowledge management (PKM) tool that grows as you do!
minisign - A dead simple tool to sign files and verify digital signatures.
helm-secrets - A helm plugin that help manage secrets with Git workflow and store them anywhere
OpenKeychain - OpenKeychain is an OpenPGP implementation for Android.
emanote - Emanate a structured view of your plain-text notes