encfs icon indicating copy to clipboard operation
encfs copied to clipboard

Have the security issues of the EncFS been addressed?

Open myous opened this issue 4 years ago • 9 comments

The EncFs was audited sometime ago, where a number of security issues were found. Have these issues been addressed?

myous avatar Apr 20 '20 22:04 myous

I also would like to know this. Could you please address this in the README in both cases?

TamasBarta avatar Apr 23 '20 14:04 TamasBarta

The Arch wiki still says these are not resolved. I skip installing encfs for now, but please provide an edit for the Arch wiki as well, if the issues are actually resolved.

TamasBarta avatar Apr 23 '20 15:04 TamasBarta

Yes I would like to know as well!

mgoldau avatar May 18 '20 06:05 mgoldau

I'm also concerned.

J053Fabi0 avatar Jun 10 '20 06:06 J053Fabi0

Any updates?

ulwanski avatar Aug 31 '20 20:08 ulwanski

Well given no pull requests since 2018. I believe the main coder just stopped after all these years. Amazing as many that have used and benefited no one is picking it up.

As far as the Arch wiki that looks to be pointing to as of 1.74 and an audit from 2014 so quite dated. We are now on 1.95 2018. (2yr ago). Look at the change notes. So many other apps used this as their roadmap. Someone should fork this and keep continue or try and contact original and get it officially transfered.

TimFW avatar Dec 06 '20 01:12 TimFW

See https://github.com/rfjakob/gocryptfs for a possible alternative. The readme for that project says it was created in part to resolve the security issues present in this project.

rsyring avatar Oct 04 '21 01:10 rsyring

The EncFs was audited sometime ago

@myous I believe the audit you are referencing was the one posted to the EncFS mailing list in case anyone wanted the original source:

  • https://sourceforge.net/p/encfs/mailman/message/31849549/

brianddk avatar Dec 28 '21 21:12 brianddk

It would be nice to have a kind of official statement about the project status from @vgough : no release since 2018 and last commit from @benrubson in 2020 are not really great signs :( But as it is quite a security sensitive project, a "project is discontinued, don't use it, use XYZ instead" could be an important information, as there are most probably still many users around.

In any case, thanks a lot for your work the last years, it was (and still is) a very useful tool!

omueller avatar Jan 06 '22 13:01 omueller