{"repo":"PentHertz/LUKSbox","free":true,"listed":false,"github":"https://github.com/PentHertz/LUKSbox","clone":"git clone https://github.com/PentHertz/LUKSbox.git","description":"Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0/SEP, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots. Mounts as a real drive on Linux, macOS, and Windows.","language":"Rust","stars":725,"topics":["encryption","file","secure","sensitive-data","vault"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"LUKSbox Encrypted vaults that survive the next decade. Open-source, FIDO2 + TPM 2.0 native, post-quantum-ready. Store sensitive files in the cloud or on shared media without trusting the host. Built by Website Docs Security Fuzzing Compare --- What it solves You probably already store sensitive files where you don't fully control the storage: cloud sync (iCloud, Drive, Dropbox, OneDrive, S3, Backblaze), NAS units, USB sticks that travel, backup tapes that end up at a recycler. The provider promises encryption-at-rest \"with their keys.\" LUKSbox encrypts the file before it ever leaves your machine, under your keys, in a single container that is opaque to the provider and tamper-evident on the way back. A LUKSbox vault is one file ( .lbx ), optionally with a separate header ( .hdr ) and post-quantum sidecar ( .kyber ) that you keep on different storage. Drop it on any cloud or shared medium. The provider sees one indistinguishable-from-random blob and cannot decrypt it even under legal compulsion. Mount it locally as a real drive when you need to use it. Concern Plain cloud upload Cloud + provider encryption LUKSbox vault on cloud --- --- --- --- Provider can read your files Yes Yes (they hold the key) No Government request to provider exposes data Yes Yes No Silent file tamper detected No Sometimes (TLS in transit only) Yes (per-chunk AEAD) Whole-vault rollback detected No No Yes (anchor sidecar) \"Harvest now, decrypt later\" (post-quantum) Vulnerable Vulnerable ML-KEM-768/1024 ","default_branch":null,"files":null,"tree":[],"storefront":"/r/PentHertz","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/PentHertz/LUKSbox/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}