27 comments

[ 3.6 ms ] story [ 8.5 ms ] thread
I like this idea.

What's your security/cryptography background?

Steganography is sort of an art.

But standardized and verified digital encryption routines are available in modern operating systems to make strong cryptography available and accessible to the average developer.

Why is that a reply to my comment?
You asked about cryptography experience.

I was atempting to point out that you don't necessarily need crypto experience to implement strong cryptography. The part that really demands experience has already been done and is readily available.

Well, I'll assume you know what you're talking about.

What level of trust do you grant to this project?

As I said, strong crypto is readily available but the question is, did he make use of it?

Impossible to say without seeing the implementation/source code.

No. Sort of maths.

One is not supposed to trust "art" with their passwords.

"Art" as in there are different implementations but none that are standardized, proven secure and readily available (that I am aware of) as a local service.
AI webpage?
This seems like the end result of one of those "chatgpt - make me a business" online courses. There's no information about who's behind it, AI generated content everywhere, etc.
I built something similar years ago --- data hidden locally in plain sight.

Instead of stenography, I simply appended the encrypted data/payload to the end of a JPG file in my photo library. The file opens and displays normally.

Part of the photo/carrier file is used as salt for decryption. The part that is used changes randomly based on the last modification time of the file. The file creation time is maintained/doesn't change with payload modifications.

Encryption is also tied to disk parameters so a simple file copy makes the data unreadable. The access utility can be used to move the file and re-encrypt the data on a different disk.

Sloppy slop.

A strong password and strong encryption is enough. The presence of 'blindlock' on a device is a clear indication that one of your files is a wallet. Phoning home to do a licence check is EVERY time you use it is obnoxious and defeats the purpose of having local software.

I recently learned Steganography, as correctly named in the article, is not the same as Stenography.
Yes, similar to how an apple and a pineapple are not the same.
i bet they stuff the data into a PNG chunk next to the image data, so they aren't even doing steganography
no source code == no security.
I think I'll ask Codex to make an open source version
The question is, have you done something so unique and challenging that your website itself wouldn't serve as a prompt to rebuild the whole thing? Would I spend less than $49 doing so?
> password vault

I see "pricing" but can't spot "source code", perhaps you forgot to add a link?