11.58 RC3: Disagree with degradation for header-encrypted archives

English support forum

Moderators: Stefan2, Hacker, petermad

User avatar
Flint
Power Member
Power Member
Posts: 3550
Joined: 2003-10-27, 09:25 UTC
Location: Belgrade, Serbia
Contact:

11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *Flint »

Unfortunately I missed the heated discussion about header-encrypted archives, but I completely disagree with how TC is becoming completely crippled in that area.

Improved security? Sign me in. Hiding information from peeping eyes? Totally agree. Making it all completely and utterly non-configurable? Absolutely not!!!

Come on, I'm sitting in my apartment, completely alone, with my windows blinded — and I'm not allowed to keep the current directory in the archive when I switch between tabs, just because its name is in the tab header? Even though I was just showing the full archive content on my screen? Total Commander has always been about flexibility and configurability. We had an option. It was set to the most secure setting by default. And to change it, the user specifically has to go to the INI configuration and change the value. Not even a random "just give me everything insecure", he has to read about what values are accepted, and deliberately choose something that's acceptable. How is that insecure?

What next, getting rid of F8 just because somebody pressed Enter too hastily and now blames Christian for the loss of data?

TC is a great tool for advanced users, for those who know a lot about how to deal with information. Keep the default settings whatever you see fit, but don't remove the settings themselves! Don't turn it into a crippled restricted program for people who have no idea how to use it - they have their perfectly working Explorer.
Flint's Homepage: Full TC Russification Package, VirtualDisk, NTFS Links, NoClose Replacer, and other stuff!
 
Using TC 11.56 / Win10 x64
User avatar
Horst.Epp
Power Member
Power Member
Posts: 7573
Joined: 2003-02-06, 17:36 UTC
Location: Germany

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *Horst.Epp »

2Flint
I also argued against such functions and said
TC should not try to hide my data from myself.
Windows 11 Home, Version 25H2 (OS Build 26200.8737)
TC 11.58 x64 / x86
Everything 1.5.0.1416b (x64), Everything Toolbar 2.4.1
QAP 12.3 x64, Listary Pro 7.0.0.3 beta
User avatar
beb
Power Member
Power Member
Posts: 762
Joined: 2009-09-20, 08:03 UTC
Location: Odesa, Ukraine

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *beb »

I agree with those early-bird guys over here.
Please, make it configurable.
#278521 User License
Total Commander [always the latest version, including beta] x86/x64 on Win10 x64/Windows 11/Android 17
JOUBE
Power Member
Power Member
Posts: 1927
Joined: 2004-07-08, 08:58 UTC

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *JOUBE »

Same for me. Otherwise, things are going in the wrong direction for a professional tool like the TC. It’s not the case that those who constantly write up are automatically right. On the contrary: the supposed "users" being referred to - and on whose behalf the writers is supposedly speaking - do not exist at all. 2ghisler(author) Please make it optional. Thanks to user Flint to open this thread.
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 53138
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *ghisler(Author) »

The argument was that Total Commander should not have any options which are insecure, otherwise a bad actor could modify your wincmd.ini and hope that you keep a tab with a protected name open.
Author of Total Commander
https://www.ghisler.com
User avatar
Horst.Epp
Power Member
Power Member
Posts: 7573
Joined: 2003-02-06, 17:36 UTC
Location: Germany

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *Horst.Epp »

Make this new behavior default, but optional
and no one should complain.
Windows 11 Home, Version 25H2 (OS Build 26200.8737)
TC 11.58 x64 / x86
Everything 1.5.0.1416b (x64), Everything Toolbar 2.4.1
QAP 12.3 x64, Listary Pro 7.0.0.3 beta
JOUBE
Power Member
Power Member
Posts: 1927
Joined: 2004-07-08, 08:58 UTC

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *JOUBE »

ghisler(Author) wrote: 2026-06-11, 10:03 UTC The argument was that Total Commander should not have any options which are insecure, otherwise a bad actor could modify your wincmd.ini and hope that you keep a tab with a protected name open.
2ghisler(author)That’s far-fetched. TC users need to know what they’re doing; that’s always been the case with TC in the past and now and in the future. The senseless, time-wasting nitpicking about "spaces" and so is completely overblown and hinders the substantive development of TC. Some people are barking up the wrong tree, and I have long hoped that you ghisler(author) would finally stop barking with them. Unfortunately, the forum is increasingly becoming cluttered with this, and that is not in the spirit of the TC as I know and appreciate it. And the frequently mentioned "users" affected by this don't actually exist - or rather, they are the writers themselves and no one else. In my view, this is not in the TC's interest. I think if you - ghisler (author) - are hoping to put this behind you at some point, you are mistaken. There is always something to be found... And ultimately, that drains TC of its energy.
Last edited by JOUBE on 2026-06-11, 11:12 UTC, edited 2 times in total.
User avatar
Flint
Power Member
Power Member
Posts: 3550
Joined: 2003-10-27, 09:25 UTC
Location: Belgrade, Serbia
Contact:

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *Flint »

ghisler(Author) wrote: 2026-06-11, 10:03 UTC The argument was that Total Commander should not have any options which are insecure, otherwise a bad actor could modify your wincmd.ini and hope that you keep a tab with a protected name open.
If we have a bad actor that has full access to our file system, encrypted archives are usually not our highest concern. The said bad actor could easily replace TC executable with TC 11.57, for example, and have the same effect. Or run a screen-recording software, and watch everything that the legitimate user has seen. You can never prevent all that.

Enforcing on-the-spot restrictions against user's own privileges has never been a good idea in security. If we are authorized, we have access — that's the fundamental definition of permissions. If we don't want access, it must be configured via restricting permissions, not by occasional hiding information we have full access to.

If you go into this battle, you will only keep making the legitimate user's life miserable, but not really prevent the "hacker" from dealing damage.
Flint's Homepage: Full TC Russification Package, VirtualDisk, NTFS Links, NoClose Replacer, and other stuff!
 
Using TC 11.56 / Win10 x64
JOUBE
Power Member
Power Member
Posts: 1927
Joined: 2004-07-08, 08:58 UTC

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *JOUBE »

Flint wrote: 2026-06-11, 11:06 UTC If we have a bad actor that has full access to our file system, encrypted archives are usually not our highest concern. The said bad actor could easily replace TC executable with TC 11.57, for example, and have the same effect. Or run a screen-recording software, and watch everything that the legitimate user has seen. You can never prevent all that.

Enforcing on-the-spot restrictions against user's own privileges has never been a good idea in security. If we are authorized, we have access — that's the fundamental definition of permissions. If we don't want access, it must be configured via restricting permissions, not by occasional hiding information we have full access to.

If you go into this battle, you will only keep making the legitimate user's life miserable, but not really prevent the "hacker" from dealing damage.
Je suis tout à fait d'accord.
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 53138
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *ghisler(Author) »

Well now they start o complain about log files:
viewtopic.php?t=87751
I really don't know where this will end. I will probably have to remove support for header-encrypted archives altogether. :(
Author of Total Commander
https://www.ghisler.com
User avatar
KozakMak
Power Member
Power Member
Posts: 741
Joined: 2021-05-24, 12:39 UTC
Location: UA

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *KozakMak »

2ghisler(Author)

Cybersecurity > Comfort

"This is the way" (с)
OS: Win11 | TC: latest x64
User avatar
Flint
Power Member
Power Member
Posts: 3550
Joined: 2003-10-27, 09:25 UTC
Location: Belgrade, Serbia
Contact:

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *Flint »

2ghisler(Author)
I think, from this topic it's quite clear that a significant amount of people consider this direction completely ridiculous. TC has never been targeting unqualified home users. Regardless of what a select minority of users tries to enforce, it's not, and I repeat — it's NOT a security vulnerability, if the program does not show this behavior with default settings. When a user turns some settings on (or let somebody else do it), he/she accepts full responsibility. That's it, simple as that.
Flint's Homepage: Full TC Russification Package, VirtualDisk, NTFS Links, NoClose Replacer, and other stuff!
 
Using TC 11.56 / Win10 x64
larry99
Junior Member
Junior Member
Posts: 88
Joined: 2009-01-16, 16:03 UTC
Location: Germany

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *larry99 »

Following the logic of the vulnerablity argument it should not be allowed to unpack a header-encrypted archive at all:
You use the password once and after that all the file names and even the contents is visible on the system.

The misconception is that encrypted archives are not encrypted to prevent the content to be seen but to secure the content in *untrusted* environments like email, off site backups and similar. If your own computer is not trusted you should not view sensible information on it to begin with.
User avatar
Flint
Power Member
Power Member
Posts: 3550
Joined: 2003-10-27, 09:25 UTC
Location: Belgrade, Serbia
Contact:

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *Flint »

And never type any passwords anywhere! Do not login on web sites and forums, or, God forbid, on banking web sites! Just imagine: you open your full bank account details, the sums, incomes and spendings, and it's all VISIBLE ON SCREEN! And even more, it does not log you off immediately when you switch to another tab! Totally unacceptable, let's write to all the banks world-wide that they must immediately change it.

And if you have a Bitlocker-encrypted disk — don't even think of booting your computer and logging in, because absolutely everything that was encrypted on your disk will become accessible! That's a nightmare! We will all die!!! :shock:
Flint's Homepage: Full TC Russification Package, VirtualDisk, NTFS Links, NoClose Replacer, and other stuff!
 
Using TC 11.56 / Win10 x64
CrMaReLi
Junior Member
Junior Member
Posts: 11
Joined: 2017-01-09, 10:54 UTC

Re: 11.58 RC3: Disagree with degradation for header-encrypted archives

Post by *CrMaReLi »

ghisler(Author) wrote: 2026-06-12, 07:35 UTC Well now they start o complain about log files:
viewtopic.php?t=87751
I really don't know where this will end. I will probably have to remove support for header-encrypted archives altogether. :(
I think that if that users want to preserve their encrypted archives so much they should use another software, set up their logs correctly to point to a safe location, use internal associations to set up opening their archives in an external software and finally - just use VeraCrypt on top of that (since it blocks Copilor, part of telemetry etc). And if they are that paranoid - use a hidden container in VeraCrypt partition (basically if you put one password, you get your files, but if you put a fake one, you get another set of files completely).

Total Commander is not something they try to make you to believe it is. It's a highly configurable file manager with a lot of powerfull options. And great power comes with great responsibility.

And some more of my 2 cents. In an opensource community (I'm a linux user) there is also a rise of such "malicious" actors, who disrupt the whole process of development whith their slop bug reports and unreasonable demands.

Remember - Total Commander is your software. Not theirs. You can do whatever you want with it. And even me, as an example, who bought a license, can't dictate you what to do with it. The only thing user can do with Total Commander is to decide to use or not to use it. And maybe provide some bug reports.
Post Reply