关于GPG对称加密文件编辑脚本的安全优化及无临时文件实现的技术问询
GPG对称加密文件编辑脚本的安全优化及无临时文件实现的技术问询
我最近写了个脚本,能让用户用Vim编辑GPG加密的文件,目前已经搞定了非对称加密的版本,代码如下:
#!/bin/sh # TODO: add support for symmetric encryption if [ $# -ne 1 ]; then echo "Needs two arguments, exiting" exit else file="$1" fi if [ -z "$EDITOR" ]; then editor="vim" else editor=$EDITOR fi tmp_file="$(mktemp)" gpg -d --yes -o "$tmp_file" "$file" gpg_exit=$? if [ $gpg_exit -ne 0 ]; then echo "Decryption failed, exiting" rm $tmp_file exit fi original_mod_time=$(stat -c %Y "$tmp_file") $editor "$tmp_file" new_mod_time=$(stat -c %Y "$tmp_file") if [ "$original_mod_time" -ne "$new_mod_time" ]; then gpg -o "$file" -e --yes -r recipient "$tmp_file" gpg_exit=$? if [ $gpg_exit -ne 0 ]; then echo "Encryption failed, exiting" fi fi shred -u "$tmp_file"
不过现在我想给脚本加上对称加密支持,但遇到个问题:不想让用户输入两次密码——既容易输错又挺烦人的。我知道可以读取密码后传给GPG,但用gpg --passphrase $passphrase这种方式不安全,因为系统里的任何进程都能读取命令行参数。有没有其他安全的方式来传递密码?我绝对不想把密码存在文件里。
另外还有个想法:有没有办法完全不用创建临时文件来实现这个脚本?这样安全性会更高,我大概想象的流程是这样的:gpg -d $file | vim --some-option | gpg -c -o $file,但不知道具体怎么落地实现。
备注:内容来源于stack exchange,提问作者Jeff
相关产品推荐
相关产品推荐

