# Open Source Encryption Software

**URL:** <https://boards.straightdope.com/t/open-source-encryption-software/549464>\
**Category:** Factual Questions\
**Created:** [August 6, 2010, 11:30pm UTC](https://boards.straightdope.com/t/open-source-encryption-software/549464 "2010-08-06T23:30:56Z")\
**Posts on this page:** 3\
**Page:** 3

<div class="post-metadata">

**Author:** ![Steve\_MB](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/steve_mb/32/5339_2.png) [@Steve\_MB](https://boards.straightdope.com/u/Steve_MB)\
**Post date:** [August 13, 2010, 7:44pm UTC](https://boards.straightdope.com/t/open-source-encryption-software/549464/41 "2010-08-13T19:44:11Z")

</div>

> [@Cartooniverse](#):
>
> 1. Can these packages fail, locking me out for good?

There are two ways you could get “locked out for good”:

1. The encrypted file is corrupted. Because strong encryption necessarily strips out as much redundancy as possible from the original data (any remaining redundancy provides clues that help crack the encryption), an encrypted volume is more vulnerable to being irreversibly scrambled by bit errors than an equivalent amount of raw unencrypted data.

Solution: Keep backups. For obvious reasons, these should be extra copies of the encrypted files, not copies of the original data. (Also keep backup copies of the encryption software, though something like TrueCrypt should be easy enough to find and re-download if necessary.)

1. You forget your passphrase.

Solution: Keep a record of your passphrase in a secure location, or make damn sure it’s something you won’t forget. For the latter option, you probably want to pick a technique for generating a long pseudorandom string from an easily memorized phrase – “first letter of each word” works well enough if you have enough words.

---

<div class="post-metadata">

**Author:** ![Ximenean](https://avatars.discourse-cdn.com/v4/letter/x/aca169/32.png) [@Ximenean](https://boards.straightdope.com/u/Ximenean)\
**Post date:** [August 13, 2010, 8:02pm UTC](https://boards.straightdope.com/t/open-source-encryption-software/549464/42 "2010-08-13T20:02:25Z")

</div>

> [@GiantRat](#):
>
> I understand OTPs perfectly well. My point is that the general law of probability, for example (that which can happen will happen) means that, given processing power and time, you’ll come across a match; kind of like the monkeys writing Shakespeare thing. I’m in no way implying that it’s easy or that one would even know that they’d gotten it right.

Well, I am still not sure that you do understand OTPs. Probability is irrelevant. It’s not merely very difficult to decipher OTPs without the key, it is absolutely, 100% impossible. Not just 99.9999999%, monkey-Shakespeare impossible. Utterly impossible.

---

<div class="post-metadata">

**Author:** ![Cartooniverse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cartooniverse/32/3084_2.png) [@Cartooniverse](https://boards.straightdope.com/u/Cartooniverse)\
**Post date:** [August 13, 2010, 9:41pm UTC](https://boards.straightdope.com/t/open-source-encryption-software/549464/43 "2010-08-13T21:41:12Z")

</div>

> [@Steve\_MB](#):
>
> For the latter option, you probably want to pick a technique for generating a long pseudorandom string from an easily memorized phrase – “first letter of each word” works well enough if you have enough words.

This is where I was going with a pass phrase. Words interspersed with numbers. Something that resonates with me yet is not a logical sequence.

Definitely will use as many characters as I am allowed to.

Thank you all for the expert as well as lay replies. Good Straight Dope !!!

[Previous page](https://boards.straightdope.com/t/open-source-encryption-software/549464.md?page=2)
