Skip to content

Current security status #659

Open
Open
@jsfan3

Description

Hello,
I would like to thank you for encfs. I just recently discovered it. It is very helpful with rsync because of the --reverse option. I have done several tests and am satisfied with it.

On the web, the use of encfs is discouraged because of a certain security audit from years ago. Even the Linux Mint package manager, when installing encfs, shows a warning window for possible security problems.

My feeling is that these are excessive concerns, however, I would like some information about them.

I wonder therefore:

  • Have the problems raised in that audit been resolved?
  • Having as a goal encrypted backups on a remote server of mine (a rented VPS) via rsync + encfs + --reverse option, are there real security issues or are they negligible?
  • Does it change anything if a hypothetical attacker has access to the .encfs6.xml file because it is saved with the backup on the remote server?

I appreciate your clarification.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions