[GNC] Backup to encrypted 7zip file

Stephen M. Butler kg7je at arrl.net
Wed May 13 14:04:40 EDT 2020


Encryption is very personal and also very hard to get right. 
1.  Personal.  You might prefer a commercial product (PGP) while I
prefer open source (GnuPG).
2.  Hard.  Simply XOR and many short-bit keys are now easily breakable. 
Even those who create methods (two-fish, RSA, etc) make mistakes that
leave loop-holes open to be exploited.
   (See commentary by Bruce Schneier -- https://www.schneier.com/)

So, 'tis better to use a tool built for encryption to do that work than
to expect all other tools to implement (poorly) same.  Pick the right
tool for the job rather than expecting a screw-driver to drive a nail
(or clamp two boards together).

While at it, remember that if you are not on your own box, simply having
your key available means that your data is compromised.  Any key-stroke
logger on the company machine could capture the key as you type it in
(from memory). 

So, why are you putting your personal data on a company supplied
machine?  Your data is already compromised even with attempting to
encrypt it.

On 5/13/20 12:36 AM, flywire wrote:
> Er ... no encryption.
>
> https://wiki.gnucash.org/wiki/FAQ#Q:_Can_you_please_add_a_password_feature.3F
> ...[No]
>
> The actual problem is access to personal data on a work supplied computer.
> An optional program based backup is more appropriate. GnuCash won't install
> but thankfully there is a portable version
> https://bugs.gnucash.org/show_bug.cgi?id=797740
>
> _______________________________________________
> gnucash-user mailing list
> gnucash-user at gnucash.org
> To update your subscription preferences or to unsubscribe:
> https://lists.gnucash.org/mailman/listinfo/gnucash-user
> If you are using Nabble or Gmane, please see https://wiki.gnucash.org/wiki/Mailing_Lists for more information.
> -----
> Please remember to CC this list on all your replies.
> You can do this by using Reply-To-List or Reply-All.


-- 
Stephen M Butler, PMP, PSM
Stephen.M.Butler51 at gmail.com
kg7je at arrl.net
253-350-0166
-------------------------------------------
GnuPG Fingerprint:  8A25 9726 D439 758D D846 E5D4 282A 5477 0385 81D8




More information about the gnucash-user mailing list