Comment by thih9

2 days ago

Is there a scenario where this solution would be preferable to an encrypted zip archive?

My guess is some heavily locked down systems. But perhaps there is more?

Author here. For the main use case that motivated my building this (securely sharing sensitive-ish data with non-technical people), yes, a ZIP file may have been preferable. That is what I was using before making this.

ZIP files can use two types of encryption, ZipCrypto or AES. As the sibling comment points out, ZipCrypto is pretty broken. IIRC the AES encryption is OK or mostly OK, but it's not universally supported, so your recipient may or may not be able to open the file you send them. Notably, the Windows built-in ZIP implementation didn't support ZipCrypto (this may have changed now that Windows ships with bsdtar / libarchive).

Subjectively, I feel this can be simpler to use (mostly for the recipient). You can host it at some server, share the link and the password and the recipient can access it like a regular website and get a plaintext download file. Compare that with a ZIP file, which with the same flow give you a ZIP download: if they don't immediately extract it, then they may have to hunt for the password later.

ZIP encryption is quite flawed.

That being said, I can see this being useful for a similar use case where encrypted ZIPs are useful. When malware testing, you sometimes want to avoid accidentally running the malware or exposing it to antivirus software until briefly before testing begins. Encrypted zips (as well as simple transformations like ROT13 or reversing the bytes in the file) can help control the moment the malware is unleashed. This HTML based tool could be useful for doing this in network sandboxed systems, with the specific property that it's testing the antivirus behavior when the file is marked as browser downloaded.