11.58 RC3: Disagree with degradation for header-encrypted archives
Moderators: Stefan2, Hacker, petermad
11.58 RC3: Disagree with degradation for header-encrypted archives
Unfortunately I missed the heated discussion about header-encrypted archives, but I completely disagree with how TC is becoming completely crippled in that area.
Improved security? Sign me in. Hiding information from peeping eyes? Totally agree. Making it all completely and utterly non-configurable? Absolutely not!!!
Come on, I'm sitting in my apartment, completely alone, with my windows blinded — and I'm not allowed to keep the current directory in the archive when I switch between tabs, just because its name is in the tab header? Even though I was just showing the full archive content on my screen? Total Commander has always been about flexibility and configurability. We had an option. It was set to the most secure setting by default. And to change it, the user specifically has to go to the INI configuration and change the value. Not even a random "just give me everything insecure", he has to read about what values are accepted, and deliberately choose something that's acceptable. How is that insecure?
What next, getting rid of F8 just because somebody pressed Enter too hastily and now blames Christian for the loss of data?
TC is a great tool for advanced users, for those who know a lot about how to deal with information. Keep the default settings whatever you see fit, but don't remove the settings themselves! Don't turn it into a crippled restricted program for people who have no idea how to use it - they have their perfectly working Explorer.
Improved security? Sign me in. Hiding information from peeping eyes? Totally agree. Making it all completely and utterly non-configurable? Absolutely not!!!
Come on, I'm sitting in my apartment, completely alone, with my windows blinded — and I'm not allowed to keep the current directory in the archive when I switch between tabs, just because its name is in the tab header? Even though I was just showing the full archive content on my screen? Total Commander has always been about flexibility and configurability. We had an option. It was set to the most secure setting by default. And to change it, the user specifically has to go to the INI configuration and change the value. Not even a random "just give me everything insecure", he has to read about what values are accepted, and deliberately choose something that's acceptable. How is that insecure?
What next, getting rid of F8 just because somebody pressed Enter too hastily and now blames Christian for the loss of data?
TC is a great tool for advanced users, for those who know a lot about how to deal with information. Keep the default settings whatever you see fit, but don't remove the settings themselves! Don't turn it into a crippled restricted program for people who have no idea how to use it - they have their perfectly working Explorer.
Flint's Homepage: Full TC Russification Package, VirtualDisk, NTFS Links, NoClose Replacer, and other stuff!
Using TC 11.56 / Win10 x64
Using TC 11.56 / Win10 x64
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
2Flint
I also argued against such functions and said
TC should not try to hide my data from myself.
I also argued against such functions and said
TC should not try to hide my data from myself.
Windows 11 Home, Version 25H2 (OS Build 26200.8737)
TC 11.58 x64 / x86
Everything 1.5.0.1416b (x64), Everything Toolbar 2.4.1
QAP 12.3 x64, Listary Pro 7.0.0.3 beta
TC 11.58 x64 / x86
Everything 1.5.0.1416b (x64), Everything Toolbar 2.4.1
QAP 12.3 x64, Listary Pro 7.0.0.3 beta
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
I agree with those early-bird guys over here.
Please, make it configurable.
Please, make it configurable.
#278521 User License
Total Commander [always the latest version, including beta] x86/x64 on Win10 x64/Windows 11/Android 17
Total Commander [always the latest version, including beta] x86/x64 on Win10 x64/Windows 11/Android 17
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
Same for me. Otherwise, things are going in the wrong direction for a professional tool like the TC. It’s not the case that those who constantly write up are automatically right. On the contrary: the supposed "users" being referred to - and on whose behalf the writers is supposedly speaking - do not exist at all. 2ghisler(author) Please make it optional. Thanks to user Flint to open this thread.
- ghisler(Author)
- Site Admin

- Posts: 53138
- Joined: 2003-02-04, 09:46 UTC
- Location: Switzerland
- Contact:
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
The argument was that Total Commander should not have any options which are insecure, otherwise a bad actor could modify your wincmd.ini and hope that you keep a tab with a protected name open.
Author of Total Commander
https://www.ghisler.com
https://www.ghisler.com
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
Make this new behavior default, but optional
and no one should complain.
and no one should complain.
Windows 11 Home, Version 25H2 (OS Build 26200.8737)
TC 11.58 x64 / x86
Everything 1.5.0.1416b (x64), Everything Toolbar 2.4.1
QAP 12.3 x64, Listary Pro 7.0.0.3 beta
TC 11.58 x64 / x86
Everything 1.5.0.1416b (x64), Everything Toolbar 2.4.1
QAP 12.3 x64, Listary Pro 7.0.0.3 beta
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
2ghisler(author)That’s far-fetched. TC users need to know what they’re doing; that’s always been the case with TC in the past and now and in the future. The senseless, time-wasting nitpicking about "spaces" and so is completely overblown and hinders the substantive development of TC. Some people are barking up the wrong tree, and I have long hoped that you ghisler(author) would finally stop barking with them. Unfortunately, the forum is increasingly becoming cluttered with this, and that is not in the spirit of the TC as I know and appreciate it. And the frequently mentioned "users" affected by this don't actually exist - or rather, they are the writers themselves and no one else. In my view, this is not in the TC's interest. I think if you - ghisler (author) - are hoping to put this behind you at some point, you are mistaken. There is always something to be found... And ultimately, that drains TC of its energy.ghisler(Author) wrote: 2026-06-11, 10:03 UTC The argument was that Total Commander should not have any options which are insecure, otherwise a bad actor could modify your wincmd.ini and hope that you keep a tab with a protected name open.
Last edited by JOUBE on 2026-06-11, 11:12 UTC, edited 2 times in total.
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
If we have a bad actor that has full access to our file system, encrypted archives are usually not our highest concern. The said bad actor could easily replace TC executable with TC 11.57, for example, and have the same effect. Or run a screen-recording software, and watch everything that the legitimate user has seen. You can never prevent all that.ghisler(Author) wrote: 2026-06-11, 10:03 UTC The argument was that Total Commander should not have any options which are insecure, otherwise a bad actor could modify your wincmd.ini and hope that you keep a tab with a protected name open.
Enforcing on-the-spot restrictions against user's own privileges has never been a good idea in security. If we are authorized, we have access — that's the fundamental definition of permissions. If we don't want access, it must be configured via restricting permissions, not by occasional hiding information we have full access to.
If you go into this battle, you will only keep making the legitimate user's life miserable, but not really prevent the "hacker" from dealing damage.
Flint's Homepage: Full TC Russification Package, VirtualDisk, NTFS Links, NoClose Replacer, and other stuff!
Using TC 11.56 / Win10 x64
Using TC 11.56 / Win10 x64
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
Je suis tout à fait d'accord.Flint wrote: 2026-06-11, 11:06 UTC If we have a bad actor that has full access to our file system, encrypted archives are usually not our highest concern. The said bad actor could easily replace TC executable with TC 11.57, for example, and have the same effect. Or run a screen-recording software, and watch everything that the legitimate user has seen. You can never prevent all that.
Enforcing on-the-spot restrictions against user's own privileges has never been a good idea in security. If we are authorized, we have access — that's the fundamental definition of permissions. If we don't want access, it must be configured via restricting permissions, not by occasional hiding information we have full access to.
If you go into this battle, you will only keep making the legitimate user's life miserable, but not really prevent the "hacker" from dealing damage.
- ghisler(Author)
- Site Admin

- Posts: 53138
- Joined: 2003-02-04, 09:46 UTC
- Location: Switzerland
- Contact:
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
Well now they start o complain about log files:
viewtopic.php?t=87751
I really don't know where this will end. I will probably have to remove support for header-encrypted archives altogether.
viewtopic.php?t=87751
I really don't know where this will end. I will probably have to remove support for header-encrypted archives altogether.
Author of Total Commander
https://www.ghisler.com
https://www.ghisler.com
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
2ghisler(Author)
Cybersecurity > Comfort
"This is the way" (с)
Cybersecurity > Comfort
"This is the way" (с)
OS: Win11 | TC: latest x64
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
2ghisler(Author)
I think, from this topic it's quite clear that a significant amount of people consider this direction completely ridiculous. TC has never been targeting unqualified home users. Regardless of what a select minority of users tries to enforce, it's not, and I repeat — it's NOT a security vulnerability, if the program does not show this behavior with default settings. When a user turns some settings on (or let somebody else do it), he/she accepts full responsibility. That's it, simple as that.
I think, from this topic it's quite clear that a significant amount of people consider this direction completely ridiculous. TC has never been targeting unqualified home users. Regardless of what a select minority of users tries to enforce, it's not, and I repeat — it's NOT a security vulnerability, if the program does not show this behavior with default settings. When a user turns some settings on (or let somebody else do it), he/she accepts full responsibility. That's it, simple as that.
Flint's Homepage: Full TC Russification Package, VirtualDisk, NTFS Links, NoClose Replacer, and other stuff!
Using TC 11.56 / Win10 x64
Using TC 11.56 / Win10 x64
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
Following the logic of the vulnerablity argument it should not be allowed to unpack a header-encrypted archive at all:
You use the password once and after that all the file names and even the contents is visible on the system.
The misconception is that encrypted archives are not encrypted to prevent the content to be seen but to secure the content in *untrusted* environments like email, off site backups and similar. If your own computer is not trusted you should not view sensible information on it to begin with.
You use the password once and after that all the file names and even the contents is visible on the system.
The misconception is that encrypted archives are not encrypted to prevent the content to be seen but to secure the content in *untrusted* environments like email, off site backups and similar. If your own computer is not trusted you should not view sensible information on it to begin with.
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
And never type any passwords anywhere! Do not login on web sites and forums, or, God forbid, on banking web sites! Just imagine: you open your full bank account details, the sums, incomes and spendings, and it's all VISIBLE ON SCREEN! And even more, it does not log you off immediately when you switch to another tab! Totally unacceptable, let's write to all the banks world-wide that they must immediately change it.
And if you have a Bitlocker-encrypted disk — don't even think of booting your computer and logging in, because absolutely everything that was encrypted on your disk will become accessible! That's a nightmare! We will all die!!!
And if you have a Bitlocker-encrypted disk — don't even think of booting your computer and logging in, because absolutely everything that was encrypted on your disk will become accessible! That's a nightmare! We will all die!!!
Flint's Homepage: Full TC Russification Package, VirtualDisk, NTFS Links, NoClose Replacer, and other stuff!
Using TC 11.56 / Win10 x64
Using TC 11.56 / Win10 x64
Re: 11.58 RC3: Disagree with degradation for header-encrypted archives
I think that if that users want to preserve their encrypted archives so much they should use another software, set up their logs correctly to point to a safe location, use internal associations to set up opening their archives in an external software and finally - just use VeraCrypt on top of that (since it blocks Copilor, part of telemetry etc). And if they are that paranoid - use a hidden container in VeraCrypt partition (basically if you put one password, you get your files, but if you put a fake one, you get another set of files completely).ghisler(Author) wrote: 2026-06-12, 07:35 UTC Well now they start o complain about log files:
viewtopic.php?t=87751
I really don't know where this will end. I will probably have to remove support for header-encrypted archives altogether.![]()
Total Commander is not something they try to make you to believe it is. It's a highly configurable file manager with a lot of powerfull options. And great power comes with great responsibility.
And some more of my 2 cents. In an opensource community (I'm a linux user) there is also a rise of such "malicious" actors, who disrupt the whole process of development whith their slop bug reports and unreasonable demands.
Remember - Total Commander is your software. Not theirs. You can do whatever you want with it. And even me, as an example, who bought a license, can't dictate you what to do with it. The only thing user can do with Total Commander is to decide to use or not to use it. And maybe provide some bug reports.

