EncryptEngine

Changelog

Full release history and version notes for EncryptEngine – File & Text Encryption.

Version 2.1.0

Latest 1 September 2026

A security and robustness release. The .eenc header is now authenticated, several paths that could destroy data without asking now ask, and everyday use no longer needs a Reset between operations.

Compatibility. This build writes a new container format and still opens files written by earlier versions, so nothing you have already encrypted becomes unreadable. But a file written by 2.1.0 cannot be opened by 2.0.0 or earlier — if you share .eenc files with someone still on 2.0.0, they need to update first.

Security

  • The .eenc header is now authenticated. Previously the header travelled unauthenticated, so its fields could be edited without detection — flipping a single byte turned “decrypt this file” into “extract this archive over a folder you pick”, and the declared cipher and recipient fingerprint were alterable too. The header is now bound into every chunk, so tampering is caught.
  • Container headers are validated before use. Unknown mode, cipher, content-kind or key-derivation values, and out-of-range iteration counts, are now reported as a corrupt file. A hostile container could previously carry an iteration count of zero (an unhandled crash) or a maximum one (an unbounded hang).
  • Private keys can no longer be stored as contacts. Pasting or importing the wrong file used to write an unprotected private key into your address book — and “Export all contacts” would then redistribute it. Public-key imports now check what they are actually being given, and reject anything under 2048 bits.
  • A corrupt or hand-edited settings file can no longer push an unusable key-derivation strength into the app.

Fixed — data loss and overwrites

  • “Delete the original after encrypting” could destroy the encrypted file too. Saving the .eenc inside the folder being encrypted meant the secure-shred pass deleted the ciphertext along with the source — and the app still reported success. Saving inside the source folder is now refused, the shred only runs once the output is verified on disk, and it asks for confirmation first.
  • Encrypting and decrypting no longer overwrite files silently. Both pages auto-suggest an output path and were bypassing the save dialog’s overwrite prompt entirely. Replacing an existing file, and extracting into a folder that is not empty, now ask first; encrypting a file over itself is refused.
  • The staging copy that folder encryption makes is now securely shredded, and anything a previous crash left behind is shredded at startup. It was a plaintext copy of the whole folder, previously left in the temporary directory and merely unlinked — which defeated the point of “delete the original after encrypting”.

Fixed

  • Identity keys, the identity index and contacts are written atomically. These used a truncate-then-write, so an interruption could leave a private key or the index half-written and unrecoverable. A save that fails is now reported rather than swallowed: a contact that never reached disk no longer sits in the list looking saved.
  • Only an unrecognised container falls back to the legacy key. The fallback used to catch every error, so a locked file, a permissions problem, or a container from a newer version was all misreported as a legacy-key failure.
  • Decrypt progress reaches 100%. It was measured against the container size, which counts header and per-chunk data that never becomes plaintext.
  • Typing quickly in the Decrypt path box can no longer leave the page describing an earlier file, a wrong password on a legacy file no longer leaves a partial output behind, and a container naming an unavailable cipher explains itself instead of surfacing a raw error.
  • Importing a large contacts file no longer freezes the window, an updated contact keeps its place in the list instead of jumping to the bottom, and unexpected errors are reported in a dialog instead of terminating the app.

Changed

  • Encrypt and Decrypt no longer lock up after each run. Both buttons used to stay disabled until you pressed Reset — which also cleared the password you were reusing — so working through several files meant a Reset between every one. A finished run now clears only the source selection and keeps the method, recipient and password.
  • Dropping several files says what it did. Only one item can be handled at a time; the extras used to be discarded silently, so it looked as though they had all worked.
  • Encrypting with a very weak password now warns once before going ahead. The identity backup already did this, and for a password-protected file it is the only thing protecting the contents.
  • Removing a contact asks for confirmation the way deleting an identity already did, “delete originals after encrypting” is remembered and no longer disagrees with the Settings copy after a restart, and turning Advanced mode on or off updates the Decrypt page immediately.

Interface

  • The recipient picker shows key fingerprints. It listed names only — two contacts named “John” were indistinguishable, and choosing the wrong one silently encrypted to the wrong key. Rows now carry the fingerprint, and the selected key is restated below the picker so it can be checked against what the recipient published.
  • Keyboard navigation is visible again. The custom navigation, tab and protection-method designs defined hover and selection states but no focus state, so keyboard focus was invisible. All four now draw a focus ring, Ctrl+Enter runs the current page and Esc cancels, and icon-only buttons and inputs carry names for screen readers.
  • Light theme — the segmented tab strip used a white-on-white hover tint that was invisible in Light mode.
  • Drop zones highlight while something is dragged over them, the title bar names the current page, the navigation rail’s selection accent is actually drawn, and protection cards grow with their text instead of clipping.

Version 2.0.0

July 2026

A ground-up rewrite with a task-first experience, a modern authenticated-encryption engine, multiple identities with portable backup — and, so 1.x users lose nothing, the ability to open old files. This release supersedes the previous 1.2.0 Store version.

Added — new engine & core app

  • Task-first interface with a Simple/Advanced two-layer design: Encrypt (file, folder, or text, with drag & drop), Decrypt (file or pasted message), Contacts, My Identity, and Settings.
  • Modern crypto engine — authenticated AES-256-GCM or ChaCha20-Poly1305; protection by password (PBKDF2-SHA256), your own key or a person's key (RSA-3072 hybrid, RSA-OAEP-SHA256), or a raw session key.
  • Self-describing .eenc container that records how each item was protected, so decryption can auto-detect it.
  • Shareable identity cards (vCard .vcf) and public-key export (.pem).
  • Single-instance guard, About/Splash screens showing the version, and a session-key generator plus a container inspector under Advanced mode.

Added — multiple identities & portable backup

  • Multiple identities — keep separate keys (e.g. Work and Personal); create, switch, and delete them (the only identity can't be deleted). Existing single identities migrate automatically.
  • Automatic key selection — an item encrypted for a specific identity opens against that identity, with a clear message if it isn't on this PC.
  • Identity backup & restore — export an identity (private key included) as a passphrase-encrypted .eeid file that survives a reinstall or moves to another PC, then restore it there. Closes the previous permanent-data-loss gap for key-based encryption.
  • Bulk contacts — export all contacts to one card file, and import many at once (de-duplicated by fingerprint, malformed entries skipped).

Added — open legacy 1.x files (decrypt-only)

  • The Decrypt screen recognizes and opens containers from the original EncryptEngine 1.x, auto-detected with no mode picking.
  • Password items (SALT: text blocks and .encv0 files) and public-key items — the old key is detected on startup and shown as a read-only "Legacy identity (v1)".

Changed

  • Encrypt / Decrypt buttons lock after a run until Reset, preventing accidental re-runs (a cancelled or invalid run stays retryable).
  • Progress for every operation — an animated bar for text/folder phases and bulk contacts, byte-level progress for files.
  • New app icon, in-app logo, and Store tiles, plus a wordmark splash.

Fixed

  • Identity name no longer bleeds when switching identities (covered by a regression test).
  • Build-number parsing for the auto-increment target.

Security

  • Private keys are sealed at rest with Windows DPAPI (CurrentUser) and never leave the process unsealed; .eeid backups are passphrase-encrypted.
  • Optional secure overwrite ("shred") of originals after encryption.
  • Note: opened legacy 1.x items have no authentication tag (the old format predates it), so a wrong password or corruption can't be cryptographically distinguished.

Version 1.0 – 1.2

January 2026

Original Release

  • RSA key pair generation on startup
  • AES-256 session key generation and RSA-encrypted key exchange
  • Text encryption and decryption using an RSA key, a pasted public key, an AES session key, or a password
  • File encryption and decryption with streaming block processing and a real-time progress bar
  • Password-based encryption with a random 16-byte salt stored alongside the ciphertext
  • Fully offline operation

Superseded by the 2.0.0 rewrite. Files and messages from 1.x can still be opened by 2.0.0 (decrypt-only).

Versions