You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于GPG对称加密文件编辑脚本的安全优化及无临时文件实现的技术问询

GPG对称加密文件编辑脚本的安全优化及无临时文件实现的技术问询

我最近写了个脚本,能让用户用Vim编辑GPG加密的文件,目前已经搞定了非对称加密的版本,代码如下:

#!/bin/sh

# TODO: add support for symmetric encryption

if [ $# -ne 1 ]; then
    echo "Needs two arguments, exiting"
    exit
else
    file="$1"
fi

if [ -z "$EDITOR" ]; then
    editor="vim"
else
    editor=$EDITOR
fi

tmp_file="$(mktemp)"

gpg -d --yes -o "$tmp_file" "$file"
gpg_exit=$?

if [ $gpg_exit -ne 0 ]; then
    echo "Decryption failed, exiting"
    rm $tmp_file
    exit
fi

original_mod_time=$(stat -c %Y "$tmp_file")
$editor "$tmp_file"
new_mod_time=$(stat -c %Y "$tmp_file")

if [ "$original_mod_time" -ne "$new_mod_time" ]; then
    gpg -o "$file" -e --yes -r recipient "$tmp_file"
    gpg_exit=$?
    if [ $gpg_exit -ne 0 ]; then
        echo "Encryption failed, exiting"
    fi
fi

shred -u "$tmp_file"

不过现在我想给脚本加上对称加密支持,但遇到个问题:不想让用户输入两次密码——既容易输错又挺烦人的。我知道可以读取密码后传给GPG,但用gpg --passphrase $passphrase这种方式不安全,因为系统里的任何进程都能读取命令行参数。有没有其他安全的方式来传递密码?我绝对不想把密码存在文件里。

另外还有个想法:有没有办法完全不用创建临时文件来实现这个脚本?这样安全性会更高,我大概想象的流程是这样的:gpg -d $file | vim --some-option | gpg -c -o $file,但不知道具体怎么落地实现。

备注:内容来源于stack exchange,提问作者Jeff

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 11:09:38