Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

Kryptor: Simple File Encryption on Linux

Kryptor is a free, open-source command-line tool for encrypting single files (PDFs, images, documents, anything). It uses modern cryptography (XChaCha20-Poly1305 and Argon2id) and has no settings to misconfigure. Websi

Kryptor is a free, open-source command-line tool for encrypting single files (PDFs, images, documents, anything). It uses modern cryptography (XChaCha20-Poly1305 and Argon2id) and has no settings to misconfigure.

Note: Kryptor has not had a public security audit. For extremely sensitive data, consider an audited tool such as VeraCrypt or Cryptomator.

Installation (Ubuntu / Debian / other Linux)

Kryptor is not in the apt repositories, so sudo apt install kryptor will fail. Install it manually:

1. Download

Go to the releases page and download the latest Linux x64 zip (for example kryptor-linux-x64.zip):

https://github.com/samuel-lucas6/Kryptor/releases

The release page also lists checksums and signatures if you want to verify the download.

2. Extract and install

cd ~/Downloads
sudo apt install unzip          # only if unzip is missing
unzip kryptor-linux-x64.zip
chmod +x kryptor
sudo mv kryptor /usr/local/bin/

If the extracted file has a different name, rename it to kryptor when moving it.

3. Check it works

kryptor --help

Usage

Encrypt a file with a passphrase

kryptor -e -p report.pdf

You will be asked to enter a passphrase. The result is a new file, report.pdf.bin. The original file is kept, so delete it yourself if you no longer want the unencrypted copy.

Decrypt a file

kryptor -d -p report.pdf.bin

Enter the same passphrase and the original file is restored.

Encrypt several files or a folder

kryptor -e -p file1.pdf file2.jpg MyFolder

Quick reference

Action Command
Encrypt with passphrase kryptor -e -p file
Decrypt with passphrase kryptor -d -p file.bin
Show all options kryptor --help

Option names and output file extensions can differ between versions, so check kryptor --help if something does not match.

Important: why -p?

Without -p, kryptor -e file uses public-key encryption and needs a key pair, giving this error:

Error: You don't have a default key pair. You can generate one using -g|--generate.

For simple passphrase-based encryption, always add -p.

Security tips

  1. Use a strong passphrase. 5 to 6 random words is a good target. The passphrase matters more than the algorithm.
  2. There is no recovery. If you forget the passphrase, the file cannot be decrypted. Store the passphrase in a password manager.
  3. Test decryption before deleting the original file.
  4. Delete the unencrypted original once you are sure the encrypted copy works. Note that a normal delete does not guarantee the data cannot be recovered from the disk.
  5. Keep backups of your encrypted files.

Alternative: GnuPG (preinstalled on most Linux systems)

# Encrypt
gpg --symmetric --cipher-algo AES256 report.pdf

# Decrypt
gpg --decrypt report.pdf.gpg > report.pdf
📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.