Error occurred when deleting folders inside an encrypted 7-Zip archive.

Bug reports will be moved here when the described bug has been fixed

Moderators: Hacker, petermad, Stefan2, white

User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 53125
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *ghisler(Author) »

Here is what I changed in Total Commander 11.58 RC2:
1. EncryptedNameCache=0 is now the default
2. I added code to handle passwords stored by plugins like Total7zip:
- Call new packer plugin function ForgetPassword or unload/reload plugin on minimize (or reload plugin if unimplemented) when the archive was header encrypted, or the user accessed encrypted files.
- When leaving archive with encrypted data with KeepPackerPassword=4 set, call new plugin function ForgetPassword. If the function is missing, unload and reload the plugin
3. Don't show error message when user tries to enter header-encrypted 7-Zip or RAR archive, but clicks Cancel in the password input dialog (only works with internal unpackers)
4. Do not store subdirectories of header-encrypted archives in wincmd.ini [lefttabs] or [righttabs]
5. When unpacking one or more unopened archives (Files - Unpack Specific Files), clear archive password when KeepPackerPassword=4 is set. The problem was that the names in the archive were never actually shown in a file panel, so leaving the archive never happened.
Author of Total Commander
https://www.ghisler.com
User avatar
petermad
Power Member
Power Member
Posts: 17375
Joined: 2003-02-05, 20:24 UTC
Location: Denmark
Contact:

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *petermad »

3. Don't show error message when user tries to enter header-encrypted 7-Zip or RAR archive, but clicks Cancel in the password input dialog (only works with internal unpackers)
Confirmed fixed in TC 11.58rc2 :-)
License #524 1994
Danish TC Translator
TC 11.58rc3 32+64bit on Windows XP 32bit & Windows 7, 8.1 & 10 (22H2) 64bit, 'Everything' 1.5.0.1415b
TC 3.62 on Android 6, 13, 15 & 16
TC Extended Menus | TC Languagebar | TC Dark Help | PHSM-Calendar
User avatar
white
Power Member
Power Member
Posts: 6940
Joined: 2003-11-19, 08:16 UTC
Location: Netherlands

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *white »

ghisler(Author) wrote: 2026-06-04, 08:04 UTC
I think each time such archive is opened, in any tab, the password should be asked
If that is your point, then I have to disagree. KeepPackerPassword=4 is not about tabs at all. ...
I wasn't talking about KeepPackerPassword=4. I have asked you to consider a different approach, which I have already tried to explain to you several times.
ghisler(Author) wrote: 2026-06-04, 08:04 UTC
To avoid having to type the password again when access was already granted in a tab, I suggested a new remember password setting, but not like your KeepPackerPassword=4 setting. While your setting forgets the password when leaving an archive, my suggested setting only forgets the password when leaving the last open protected archive.
So you mean that passwords need to be remembered per TAB, not per archive, and discarded once the user leaves the archive on that tab.
No I don't mean that. I mean that passwords are remembered per file, but that the password is forgotten (for all tabs) whenever the user tries to enter the archive on a tab (new access to the archive on a tab). This way, there is explicit permission for every new access to the archive. If the user then doesn't enter the correct the password, the user can no longer access the archive where it is open on any of the tabs. If the user enters the correct password, the user regains access to the archive on all tabs where the archive is open.
If it is possible to detect when the user leaves the archive on a tab, it seems also possible to detect the opposite, namely to detect when the user enters the archive on a tab.
ghisler(Author) wrote: 2026-06-04, 08:04 UTC I think that this is counter-intuitive. Users mostly know tabs from Web browsers, and there logging in to a web size applies to all tabs. But there is no automatic logout, so the comparison isn't fully applicable.
I think that's more of a very loose association than an analogy.
I think a comparison with encrypted file content is much more similar. Permission given to view the contents of a file and to keep viewing the contents of a file, doesn't necessarily implicitly mean permission is given to open additional windows and view the contents of the file in those windows too.
ghisler(Author) wrote: 2026-06-04, 08:04 UTC
The default option should definitely be secure. In my opinion the current behavior of EncryptedNameCache=0 isn't even secure enough. As said, I think permission to open a protected archive in a tab cannot be assumed to automatically also mean permission to open the protected archive limitless on additional tabs.
I really don't understand your obsession with tabs.
I think it is important to try to ensure that people's encrypted data remains private. Even a small and seemingly insignificant leak can have very big consequences. That's not limited by your lack of imagination.
ghisler(Author) wrote: 2026-06-04, 08:04 UTC For the user, it's unintuitive when they need to re-enter the password although the archive is currently open before their eyes. It's beyond my imagination why you consider this insecure, sorry.
You are assuming that new access to the archive is always the choice of the user. That is not necessarily the case. Duplicating a tab with an open archive, or opening a background tab with one of the decrypted folder names is extremely easy. As mentioned before, this can happen by accident (for example by typing the wrong key combination), by the cat interfering (cat is a symbol here for a multitude of ways), or by foul play (example mentioned before). And having extra tabs where the archive is open without the user's knowledge can cause that encrypted data is leaked. After working with a header-encrypted archive, the user might close the tab and think his data is not accessible without password, while this is not the case. Even an unnoticed decrypted folder name in one of the tab headers can have unforeseen consequences.
New access to encrypted data shouldn't be that easy. It should be hard, so that the user is fully aware of what he is doing and the encrypted data remains private.
User avatar
Horst.Epp
Power Member
Power Member
Posts: 7573
Joined: 2003-02-06, 17:36 UTC
Location: Germany

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *Horst.Epp »

This discussion looks a little bit like paranoia.
TC should not try to protect my data from myself.
For me, It's sufficient to get asked for the password on the first opening in a session.
If other users can open tabs with encrypted content in my TC
something is wrong with the security of my PC or I leave it open and alone.
No TC setting will prevent Trojans or viruses from getting the content.
Windows 11 Home, Version 25H2 (OS Build 26200.8737)
TC 11.58 x64 / x86
Everything 1.5.0.1416b (x64), Everything Toolbar 2.4.1
QAP 12.3 x64, Listary Pro 7.0.0.3 beta
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 53125
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *ghisler(Author) »

2Horst.Epp
I agree, that's what the current default settings do when you choose "Remember (until program is closed or minimized)". People who are more paranoid can set the new option KeepPackerPassword=4, which only remembers the password until you leave the current archive. I think that these two already cover most use cases, and I also think that they are more intuitive than what white suggests. Maybe I will add more options in a future version, but for 11.58 I think it's sufficient.

2petermad
Great, thanks for checking!

Could someone please also check the other cases?
2. To check this,
a) install Total7zip and
b) make sure that "Prefer 7-Zip plugin if installed" is checked.
c) Then enter a header-encrypted 7-Zip archive. Now Total7zip will ask you for the password. Do not check any options there!
d) With KeepPackerPassword not set, you can leave and re-enter the archive and will not be asked again for the password because Total7zip caches it.
e) Now in RC2, when you minimize and restore Total Commander, Total7zip will be unloaded and reloaded, so it will ask again for the password.
f) With KeepPackerPassword set to 4, leaving the archive will also unload and reload Total7zip, so it will ask again for the password.

4. To check this, you need to
a) Open a header-encrypted 7-zip or rar archive with subdirs
b) Go into a subdir
c) Switch to a different tab
d) Close and re-open Total Commander
Result: Instead of the subdirectory, the tab will now point to the root of the header-encrypted archive

5. To check this, you need to
a) Set KeepPackerPassword to 4
b) Unpack one (unopened!) header-encrypted archive with Alt+F9, and choose to remember the password
c) Try to enter the archive with Enter
Result: You should again be asked for the password
d) Unpack multiple selected header-encrypted archives with Alt+F9, and choose to remember the password
e) Try to enter one of the archives with Enter
Result: You should again be asked for the password
Author of Total Commander
https://www.ghisler.com
User avatar
petermad
Power Member
Power Member
Posts: 17375
Joined: 2003-02-05, 20:24 UTC
Location: Denmark
Contact:

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *petermad »

d) Close and re-open Total Commander
Result: Instead of the subdirectory, the tab will now point
This requires that "Configuration" -> "Operation" -> Save on exit" -> "Directories" is enabled - otherwise the tabs are not remembered.

d) With KeepPackerPassword not set, you can leave and re-enter the archive and will not be asked again for the password because Total7zip caches it.
e) Now in RC2, when you minimize and restore Total Commander, Total7zip will be unloaded and reloaded, so it will ask again for the password.
f) With KeepPackerPassword set to 4, leaving the archive will also unload and reload Total7zip, so it will ask again for the password.
Confirmed

d) Close and re-open Total Commander
Result: Instead of the subdirectory, the tab will now point to the root of the header-encrypted archive
Confirmed

c) Try to enter the archive with Enter
Result: You should again be asked for the password
Confirmed

e) Try to enter one of the archives with Enter
Result: You should again be asked for the password
Confirmed
License #524 1994
Danish TC Translator
TC 11.58rc3 32+64bit on Windows XP 32bit & Windows 7, 8.1 & 10 (22H2) 64bit, 'Everything' 1.5.0.1415b
TC 3.62 on Android 6, 13, 15 & 16
TC Extended Menus | TC Languagebar | TC Dark Help | PHSM-Calendar
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 53125
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *ghisler(Author) »

This requires that "Configuration" -> "Operation" -> Save on exit" -> "Directories" is enabled - otherwise the tabs are not remembered.
Yes it does! Alternatively, use menu Configuration - Save settings, then close and re-open Total Commander.
Author of Total Commander
https://www.ghisler.com
User avatar
white
Power Member
Power Member
Posts: 6940
Joined: 2003-11-19, 08:16 UTC
Location: Netherlands

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *white »

Horst.Epp wrote: 2026-06-05, 08:18 UTC This discussion looks a little bit like paranoia.
TC should not try to protect my data from myself.
For me, It's sufficient to get asked for the password on the first opening in a session.
If other users can open tabs with encrypted content in my TC
something is wrong with the security of my PC or I leave it open and alone.
No TC setting will prevent Trojans or viruses from getting the content.
I wonder if you are also against a virus scanner constantly monitoring the system, seat belts in cars, etc.

It sounds like you're not denying the risk exists, but that you think it's unlikely to occur, that victims are to blame if it happens, and that protection is pointless because it can't prevent everything. Those arguments come across as excuses to stay ignorant rather than a serious discussion of the risk. Ignoring a risk doesn't make it safer, it only makes that you ignore the risk.

I'm not suggesting to get rid of the remember password setting. I am suggesting to always ask for the password when opening a header-encrypted archive (either in current tab or by opening a new tab with the archive's contents) in the event that the remember password setting is disabled, or when an new (yet to be implemented) limited remember password setting is enabled.
ghisler(Author) wrote: 2026-06-05, 08:59 UTC 2Horst.Epp
I agree, that's what the current default settings do when you choose "Remember (until program is closed or minimized)". People who are more paranoid can set the new option KeepPackerPassword=4, which only remembers the password until you leave the current archive. I think that these two already cover most use cases, and I also think that they are more intuitive than what white suggests. Maybe I will add more options in a future version, but for 11.58 I think it's sufficient.
Are you sure you're not mixing up convenience with intuitiveness? I don't think it’s unreasonable to ask for the password on every access to protected data. It is safer and feels more secure, and it gives users confidence in the protection. Would that really be a significant inconvenience for users, and not an acceptable inconvenience in favor of security?

The mere presence of the more insecure options in wincmd.ini adds additional risks. Adding more options later, doesn't mitigate this and will probably add to the confusion.

TC already failed in being secure in previous versions, and I think that the current implementation could be a valid reason for organizations to disallow the use of TC.
User avatar
AntonyD
Power Member
Power Member
Posts: 2180
Joined: 2006-11-04, 15:30 UTC
Location: Russian Federation

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *AntonyD »

It's also very strange that this kind of option is only put in the settings file. Ok, we know about the problem with translators and delayed release dates.
But this option is so important that it's worth the fact that you can put ONLY its English and German variants and that's it. And leave it as it is.
And in the next release all translators will update its name/help.
#146217 personal license
User avatar
Horst.Epp
Power Member
Power Member
Posts: 7573
Joined: 2003-02-06, 17:36 UTC
Location: Germany

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *Horst.Epp »

white wrote: 2026-06-06, 15:44 UTC I wonder if you are also against a virus scanner constantly monitoring the system, seat belts in cars, etc.
Not at all :)
I was many years Anti-virus and Firewall admin in large companies.

For Anti-virus solutions many users try to fine tune settings which are of no practical use.
Or they think the standard firewall rules are not enough for their enhanced security needs.

For me, in TC the following simple rules are sufficient and understandable:

1. Opening password-protected archives
TC will ask for the password once in a session, also for file name encryption.
This is valid for all tabs which show this archive.

2. If the user enables to remember the password
this is only remembered while in the same session and removed on TC exit.

3. It doesn't change above rules when TC gets or loose the current focus.

4. The most important basic rules
Don't work with an Admin account by default
Never disable antivirus or firewall rules without deep knowledge
Always apply Windows updates as soon as they are available
(only if you are a Home PC user of course)
Windows 11 Home, Version 25H2 (OS Build 26200.8737)
TC 11.58 x64 / x86
Everything 1.5.0.1416b (x64), Everything Toolbar 2.4.1
QAP 12.3 x64, Listary Pro 7.0.0.3 beta
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 53125
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *ghisler(Author) »

It's also very strange that this kind of option is only put in the settings file.
I will definitely put it in the password input dialog, just not in 11.58. The current option to store the password until TC is minimized or closed is very clear.
Author of Total Commander
https://www.ghisler.com
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 53125
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *ghisler(Author) »

It sounds like you're not denying the risk exists, but that you think it's unlikely to occur, that victims are to blame if it happens, and that protection is pointless because it can't prevent everything. Those arguments come across as excuses to stay ignorant rather than a serious discussion of the risk. Ignoring a risk doesn't make it safer, it only makes that you ignore the risk.
These are completely unfounded accusations. In RC2, with default settings, it should be 100% clear for the user when others would be able to see the encrypted names:
1. When they enter a header-encrypted archive and choose NOT to save the password, they will be able to see the file names as long as they are visible in Total Commander. The moment they don't see them any more, they need to re-enter the password when re-entering the archive. Very simple, very easy to understand, doesn't depend on tabs.
2. When they enter a header-encrypted archive and choose to save the password, the description says that it will be preserved until they minimize or close Total Commander. This is also very clear to understand. Here they need to re-enter the password when TC wasn't shown the content of a header-encrypted archive and was minimized, or when it was closed.

In my opinion, it can't be any more clear to understand!
Author of Total Commander
https://www.ghisler.com
User avatar
AntonyD
Power Member
Power Member
Posts: 2180
Joined: 2006-11-04, 15:30 UTC
Location: Russian Federation

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *AntonyD »

Dear Mr. Ghisler - we are not discussing the rules of using a drinking fountain here - where everything is in plain sight and everything is immediately understandable and you don't need to put a lot of text on the accompanying sign next to it. We are discussing the security of personal data, business data. And this is an area that deserves to be given a HUGE amount of attention, not left to the belief that people will figure it out for themselves.

I have noticed more than once that you prefer to give very, very little text both in the help section and in the settings dialogs themselves.
You believe too much that people will simply understand at a half-glance what probably already seems to you like a tedious something that 'speaks' for itself.
#146217 personal license
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 53125
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *ghisler(Author) »

2AntonyD
What's your point? Where do you disagree with my above points 1 and 2? Just insulting me will not help me to figure out what you want changed.
Author of Total Commander
https://www.ghisler.com
User avatar
white
Power Member
Power Member
Posts: 6940
Joined: 2003-11-19, 08:16 UTC
Location: Netherlands

Re: Error occurred when deleting folders inside an encrypted 7-Zip archive.

Post by *white »

ghisler(Author) wrote: 2026-06-09, 09:25 UTC
It sounds like you're not denying the risk exists, but that you think it's unlikely to occur, that victims are to blame if it happens, and that protection is pointless because it can't prevent everything. Those arguments come across as excuses to stay ignorant rather than a serious discussion of the risk. Ignoring a risk doesn't make it safer, it only makes that you ignore the risk.
These are completely unfounded accusations.
Lately, you have been quoting people without mentioning the author's name, the date of the quote, and the link to the original text. As a result, texts lose much of their context, making it much more difficult for people to understand them. I hope you can switch back to how you used to do it.

The meta data of the quote is:
white wrote: 2026-06-06, 15:44 UTC
The quoted text is a direct response to Horst.Epp's words. It's an interpretation of Horst.Epp's arguments and a response to those arguments. If you read carefully, you can map my interpretations exactly onto his words.

It seems you've taken my words out of context and turned them into general accusations against you because of the way you implemented things.
ghisler(Author) wrote: 2026-06-09, 09:25 UTC In RC2, with default settings, it should be 100% clear for the user when others would be able to see the encrypted names:
1. When they enter a header-encrypted archive and choose NOT to save the password, they will be able to see the file names as long as they are visible in Total Commander. The moment they don't see them any more, they need to re-enter the password when re-entering the archive. Very simple, very easy to understand, doesn't depend on tabs.
First, it's not only about filenames, but also about decrypted folder names in tab headers and the existence of additional opened tabs for the archive contents. This is not clear to the user, because it is not communicated to the user when he enters the password. As explained, additional tabs may be opened without the user's intent. For example, a background tab with a decrypted folder name in the header might be created without the user realizing it, and without being visible to the user (background tab is added to the end and may not be visible on screen). While the folder content may not be accessible without password, the decrypted folder name is.

Second, you seem to view this with a single-user and single-computer mindset. Which settings exist and which one is active may not be known to the user. One computer might be working with a specific setting, while another computer is working with a different setting. Or a user might change a setting without another user being aware of it. This can lead users to believe that their data is inaccessible, when in fact it is accessible.
Post Reply