@@ -9,33 +9,36 @@ Like age, it features no config options, allowing for a straightforward secure f
99
1010## Disclaimer
1111
12- ** Use it at your own risk! ** (see [ LICENSE ] ( https://github.com/ndavd/agevault/blob/main/LICENSE ) )
12+ This project has been tested, but has not undergone a formal security audit, and none is planned.
1313
14- Also, this is a project in early-development and hasn't been thoroughly tested. So far, I've tested
15- it on Linux.
14+ The codebase is intentionally kept simple and readable, so you're encouraged to review it yourself
15+ before relying on it for anything sensitive.
16+
17+ ** Use at your own risk** (see [ LICENSE] ( ./LICENSE ) ).
1618
1719## Installation
1820
1921Always install the latest release to make sure you have the latest security improvements and fixes.
2022If the update has the same major version (e.g. ` v1.x.x ` ), then it's guaranteed to be backwards
2123compatible.
2224
23- Run using Nix:
25+ ### Download the pre-built binaries
26+
27+ Get them from the [ latest release] ( https://github.com/ndavd/agevault/releases/latest ) .
28+
29+ ### Using ` nix `
2430
2531``` text
2632$ nix run github:ndavd/agevault
2733```
2834
29- Download the pre-built binaries from the
30- [ latest release] ( https://github.com/ndavd/agevault/releases/latest ) .
31-
32- Or using ` go ` :
35+ ### Using ` go `
3336
3437``` text
3538$ go install github.com/ndavd/agevault@latest
3639```
3740
38- Or using ` docker ` :
41+ ### Using ` docker `
3942
4043``` text
4144$ docker build -t agevault .
@@ -76,3 +79,23 @@ my-vault UNLOCKED
7679```
7780
78814 . That's it. Do your changes, lock it again, etc.
82+
83+ ## Design
84+
85+ ` agevault ` relies entirely on ` age ` for the cryptography involved, inheriting its security. It
86+ provides the minimal infrastructure required for ` age ` to work as a directory encryption tool.
87+
88+ ` agevault ` uses a passphrase encrypted identity for a few key reasons:
89+
90+ - Extra security factor: Having the encrypted identity file or the passphrase by itself is useless.
91+ - Easier to lock: If only symmetric encryption was used, the user would need the passphrase to lock
92+ as well; this way, the vault can be locked without entering the passphrase.
93+ - Ability to support multiple keys in the future ([ planned features] ( #planned-features ) ): This makes
94+ it possible to support multiple passphrases, each corresponding to its own key, so multiple people
95+ could _ own_ the vault: any one of them can lock it, and any one of them can unlock it with their
96+ own passphrase.
97+
98+ ## Planned features
99+
100+ - Post-quantum keys
101+ - Multi-user vault support
0 commit comments