INPUT
drop file here or click to browse
KEY
drop keyfile here or click to browse
⚠ save this key — it cannot be recovered
no input
SECURITY DETAILS
- cipher
- Serpent-256-CBC + HMAC-SHA256 (Encrypt-then-MAC) via SealStream
- kdf
- Argon2id — 19 MiB RAM, 2 passes, 1 thread (OWASP 2023 minimum) for passphrase mode; HKDF-SHA256 for keyfile mode
- key
- 64 bytes (512-bit) — 32-byte encryption key + 32-byte MAC key
- iv
- 128-bit, fresh per encryption via WebCrypto getRandomValues
- format
- LVWB v2 — 38-byte header + SerpentSeal output (IV + ciphertext + HMAC)