Program Security - Secure Desktop - Print Screen Obfuscation - Speedcrypt File Encryption

Speedcrypt
File Encryption

       
A comprehensive Crypto Suite.
 Engineered by Mariano ortu.

Speedcrypt
Encrypted Files
Go to content
Security...
Encryption Engines, HASH Engines, Memory Protection
Speedcrypt provides its users with a comprehensive set of security-oriented features designed to protect data throughout the entire processing lifecycle. Each component of the system has been engineered with a strong focus on reliability, robustness, and performance, ensuring that data handling operations are consistently aligned with security best practices. The internal data flow is structured to minimize exposure, reduce risk surfaces, and enforce strict control over sensitive information. From input acquisition to final output, every stage is designed to preserve confidentiality, integrity, and operational consistency. However, it is important to clearly state that no software solution, regardless of its level of sophistication, can guarantee absolute security in isolation.

The effectiveness of any security system is inherently dependent on the environment in which it operates and on the behavior of the user. Speedcrypt is designed to perform all security-critical operations to the highest possible standard within its scope. It implements all necessary safeguards, protections, and controls expected from a modern cryptographic tool. Nevertheless, the overall security posture also requires responsible user behavior, proper system configuration, and a controlled execution environment. In this context, security must be understood as a shared responsibility: Speedcrypt enforces protection at the software level, while the user ensures that the surrounding conditions do not undermine those protections. The following sections will describe in detail the mechanisms and features implemented within Speedcrypt to achieve these goals.

Secure Desktop
✒️ Secure Desktop Environment

Speedcrypt Ver 2.0.0.0 introduces a fully rewritten Secure Desktop module, designed from scratch to provide users with a safer environment when entering sensitive information such as passwords or encryption keys. Unlike the previous version, which relied on an external project and was resource-intensive, the new Secure Desktop is much faster, lighter, and more efficient, ensuring minimal impact on system performance while maintaining a high level of security. The implementation has been refined to enforce a more strictly controlled execution context, reducing the risk of unintended interaction with external processes and improving resistance against a wide range of user-mode interception techniques.

The Secure Desktop operates by leveraging a dedicated and controlled desktop context, effectively isolating sensitive user interactions—such as credential input—from the standard operating environment. This separation ensures that input handling, window management, and focus control occur within a confined boundary, limiting the visibility and accessibility of these operations to external processes. As a result, conventional monitoring tools, including most user-space keylogging techniques based on API hooking or message interception, are significantly mitigated during critical operations. From an engineering perspective, the system introduces tighter control over window focus enforcement, input routing, and process interaction boundaries. Input events are handled within a deterministic execution path, reducing ambiguity and eliminating indirect exposure channels typically exploited by interception mechanisms.

This results in a hardened input surface, where sensitive data remains confined to a controlled execution flow during its most vulnerable phase: user entry. The design also emphasizes consistency and predictability. By isolating the input context, Speedcrypt ensures that secure operations are executed within a known and verifiable environment, reducing dependency on the behavior of the standard desktop and minimizing the risk of race conditions or focus hijacking scenarios. However, it is essential to explicitly acknowledge the inherent limitations of this approach. The Secure Desktop model, while highly effective against a broad class of threats—particularly those operating in user mode—cannot guarantee absolute protection against all forms of input interception. Advanced keylogging mechanisms operating at kernel level, exploiting vulnerable or malicious drivers, or leveraging direct access to hardware interfaces, may bypass desktop-level isolation entirely.

Furthermore, sophisticated malware with elevated privileges may interact directly with the operating system’s input stack, perform memory inspection, capture screen content, or exploit side-channel techniques that fall outside the protection scope of a desktop isolation strategy. These attack vectors operate below or beyond the abstraction layer in which the Secure Desktop provides its defenses. For this reason, the Secure Desktop must be considered as a critical but non-exhaustive layer within a broader, defense-in-depth security model. Speedcrypt integrates this mechanism to significantly reduce the attack surface during sensitive operations, providing strong protection against the majority of real-world threats encountered in standard environments.

Its effectiveness, however, is inherently dependent on the integrity of the underlying operating system, the absence of privileged or kernel-level malware, and the overall security posture of the host system. From a system design standpoint, this approach aligns with modern security engineering principles: isolating critical operations, minimizing exposure, and enforcing controlled execution boundaries, while maintaining a clear understanding of the limits imposed by the operating environment. In conclusion, the Secure Desktop represents a high-value defensive mechanism that substantially improves input security and operational reliability. However, it must operate within a trusted and properly secured system to achieve its intended level of protection, and should always be complemented by additional security controls at both system and hardware levels.
Filling of the Master Key
✒️ Master Key Strengthening and Deterministic Expansion

Speedcrypt implements an internal mechanism to detect weak or insufficiently sized input passwords and transparently reinforce them before they are used in any cryptographic operation. This process ensures that the resulting master key always meets strict structural and entropy requirements, regardless of the original input quality.
From a design perspective, the system enforces discrete length tiers for the master key:

  • Inputs shorter than 16 bytes are expanded to 16 bytes
  • Inputs between 16 and 32 bytes are expanded to 32 bytes
  • Inputs between 32 and 64 bytes are expanded to 64 bytes
  • Inputs between 64 and 128 bytes are expanded to 128 bytes

This tiered model guarantees that all derived keys conform to predefined security thresholds, eliminating the risk associated with undersized or weak user-provided passwords. The expansion process is performed through an iterative and deterministic construction based on the Blake-256 cryptographic HASH Function. Starting from the original input, the system repeatedly computes the Blake-256 digest of the current buffer and appends it to the existing data. This procedure is executed in a loop until the desired key length is reached. Each iteration increases both the size and the entropy distribution of the working buffer, effectively transforming even low-entropy inputs into structurally strong and uniformly distributed key material. The use of Blake-256 ensures high diffusion, resistance to preimage attacks, and consistent performance characteristics.

Once the required length is achieved, the buffer is truncated if necessary to match the exact target size. All intermediate buffers and temporary hash outputs are explicitly cleared from memory immediately after use, reducing the risk of residual data exposure. An additional engineering constraint is enforced to ensure compatibility with protected memory operations: the final key length is aligned to a multiple of 8 bytes. When required, secure random padding is applied using a cryptographically strong random number generator. This padding is non-deterministic and exists solely to satisfy memory protection alignment requirements, without affecting the deterministic core of the key derivation process. It is important to note that this mechanism does not simply "pad" a password, but transforms it into a cryptographically suitable master key through controlled expansion and entropy propagation.

Finally, to further strengthen resistance against precomputation attacks such as rainbow tables and to ensure uniqueness across different contexts, a cryptographic salt is incorporated into the derivation process. The SALT is combined with the original password prior to hashing, ensuring that identical passwords produce distinct master keys when different salt values are used. This combination of deterministic expansion, strong hashing, secure memory handling, and salting results in a master key derivation process that is both robust and resilient against practical attack vectors, while remaining efficient and predictable in its behavior.
File Encryption
✒️ Encryption Algorithms in Speedcrypt

Speedcrypt integrates a diverse set of cryptographic engines designed to provide strong, flexible, and context-aware protection for both file encryption and sensitive in-memory or persistent data such as strings and SALTs. The selection includes both standardized and modern primitives, covering multiple security models and operational scenarios.

File Encryption Engines

The system supports the following encryption algorithms for file protection:

  • AES (Advanced Encryption Standard)
    AES is the de facto global standard for symmetric encryption. It offers an excellent balance between security and performance, with widespread hardware acceleration (e.g., AES-NI). It is highly resistant to known cryptanalytic attacks when used with appropriate modes of operation and key sizes.

  • AES-GCM (Galois/Counter Mode)
    AES-GCM extends AES with authenticated encryption (AEAD), providing both confidentiality and integrity in a single operation. It is optimized for high throughput and is particularly suitable for modern systems requiring tamper detection alongside encryption.

  • PGP (Pretty Good Privacy)
    PGP is a hybrid encryption framework combining asymmetric and symmetric cryptography. It enables secure key exchange and data encryption, making it suitable for scenarios involving identity, trust chains, and secure data sharing.

  • IDEA (International Data Encryption Algorithm)
    IDEA is a symmetric cipher historically used in PGP. While considered secure against practical attacks, it is largely superseded by more modern algorithms but remains relevant for compatibility and legacy systems.

  • GOST (GOST R 34.12-2015 / Kuznyechik & Magma families)
    GOST algorithms originate from Russian cryptographic standards. They are designed with strong structural properties and are used in government and institutional environments requiring compliance with regional standards.

  • SERPENT
    Serpent is a finalist of the AES competition, designed with a conservative security margin. It prioritizes security over performance, making it slower but extremely robust against cryptanalysis.

  • TWOFISH
    Twofish, also an AES finalist, offers high security with efficient performance across platforms. It supports flexible key-dependent structures and remains a solid alternative to AES.

  • CAMELLIA
    Camellia is a modern symmetric cipher comparable to AES in both security and performance. It is widely used in international standards and offers strong resistance against known attacks.

  • THREEFISH
    Threefish is a tweakable block cipher designed as part of the Skein hash function. It is optimized for large data blocks and provides high performance in software, particularly in 64-bit environments.

  • KUZNYECHIK
    Kuznyechik is a modern Russian block cipher standardized in GOST R 34.12-2015. It is designed for high security and efficiency, with strong diffusion and non-linearity properties.

  • XChaCha20-Poly1305
    This is a modern AEAD construction combining the XChaCha20 stream cipher with Poly1305 authentication. It offers excellent security, high performance, and extended nonce size, making it highly resistant to nonce reuse issues.

String and SALT Encryption Engines

For sensitive internal data such as strings and SALTs, Speedcrypt employs a focused subset of high-security algorithms optimized for secure handling of small data:

  • AES
    Used in controlled contexts for deterministic and high-performance encryption of small data blocks.

  • AES-GCM
    Provides authenticated encryption, ensuring both confidentiality and integrity of strings and SALTs, reducing the risk of silent data corruption or manipulation.

  • SERPENT
    Selected for its high security margin, particularly suitable when performance is secondary to maximum resistance against cryptanalysis.

  • TWOFISH
    Offers a balance between performance and security for internal data protection.

  • THREEFISH
    Useful for environments where large block handling and 64-bit optimization are advantageous.

  • XChaCha20
    A stream cipher variant with extended nonce support, ideal for safely encrypting variable-length data such as strings.

  • XChaCha20-Poly1305
    Adds authentication to XChaCha20, ensuring integrity and authenticity of encrypted strings and SALTs.

🖊️Engineering Perspective

The architecture of Speedcrypt is designed around the following principles:

  • Algorithm Agnosticism: Users can select the most appropriate cipher based on operational needs, compliance requirements, or threat models.
  • Security Layering: Encryption is combined with strong Key Derivation Functions and SALT usage to prevent key reuse and precomputation attacks.
  • Authenticated Encryption Preference: Where possible, AEAD modes (e.g., AES-GCM, XChaCha20-Poly1305) are preferred to eliminate the need for separate integrity mechanisms.
  • Hardware Awareness: Algorithms such as AES benefit from hardware acceleration, while others (e.g., Serpent, Twofish) provide resilience in environments lacking such support.
  • Future-Resistant Design: Inclusion of modern constructions like XChaCha20 ensures robustness against evolving attack vectors and implementation pitfalls.

🖊️Security Perspective

The combination of multiple encryption primitives within Speedcrypt is not intended as redundancy, but as controlled flexibility. Each algorithm represents a different balance between:

  • Computational cost
  • Memory usage
  • Resistance to cryptanalysis
  • Suitability for specific hardware

This allows the system to adapt to a wide range of operational contexts without compromising security fundamentals.

🖊️Final Considerations

Speedcrypt is designed not only as a collection of cryptographic primitives, but as an intelligent system that actively supports the user in selecting the most appropriate algorithms based on the operational context, hardware capabilities, and security requirements. Through its internal logic, Speedcrypt assists in identifying optimal configurations, guiding the user toward encryption engines and key derivation strategies that ensure a balanced trade-off between performance, security, and reliability. This reduces the risk of improper configurations, which are often a primary source of weakness in cryptographic systems.

Furthermore, the project intentionally provides a broad and diversified set of encryption algorithms and hashing functions. This design choice is not merely technical, but also strategic: it allows Speedcrypt to remain usable and compliant in environments where certain cryptographic standards may be restricted, regulated, or subject to national policies. By offering multiple alternatives—ranging from internationally standardized algorithms to region-specific implementations—Speedcrypt ensures operational continuity across different jurisdictions, without compromising the overall security model. This approach reflects a precise engineering philosophy: adaptability without weakening security, and freedom of choice without sacrificing correctness.
Pseudo Random Number Generator
✒️ Pseudo-Random Number Generators (PRNGs) Overview

Speedcrypt provides a curated selection of pseudo-random number generators (PRNGs) to support cryptographic operations, key derivation, and SALT generation. Each generator has been selected for its combination of security, statistical quality, and suitability for different cryptographic contexts, allowing users to tailor the randomness source to their specific security requirements.

The available generators are:

  • BCRYPT – A system-level, cryptographically secure random number generator leveraging the operating system’s entropy pool. Provides high-assurance randomness suitable for key generation and SALT creation, with minimal performance overhead.

  • FORTUNA – A robust, entropy-accumulating PRNG designed to withstand partial entropy exposure. Fortuna continuously reseeds from multiple entropy sources, making it resilient against state compromise and ensuring long-term unpredictability.

  • AES-CTR DRBG – A deterministic random bit generator based on AES in counter mode. Combines the proven security of AES with deterministic expansion, providing high-speed output suitable for bulk cryptographic operations while maintaining cryptographic strength.

  • CRYPTO-RANDOM – A general-purpose cryptographically secure generator leveraging established cryptographic primitives. Offers strong statistical properties and is ideal for situations requiring fast, secure random numbers without deterministic reseeding requirements.

  • BLUM-BLUM-SHUB (BBS) – A mathematically rigorous PRNG grounded in number-theoretic hardness assumptions. Slower compared to other generators but offers provable unpredictability under standard cryptographic assumptions, making it particularly valuable for high-security key generation scenarios.

Each PRNG in Speedcrypt has been integrated with careful attention to memory handling, ensuring that generated values do not leak via residual buffers. The system enforces secure reseeding and tight alignment with the master key derivation process, maximizing cryptographic integrity. By offering this diverse set of generators, Speedcrypt empowers users to select the most appropriate randomness source for their use case, whether prioritizing speed, entropy accumulation, or provable unpredictability. This design philosophy reinforces the overall security architecture, ensuring that all cryptographic operations begin with a strong, reliable foundation of randomness.
Key Hashing and Key Derivation
✒️ Hashing Algorithms in Speedcrypt

Speedcrypt integrates a comprehensive suite of cryptographic hash functions and password-based derivation mechanisms, designed to cover a wide spectrum of security requirements, interoperability needs, and regulatory contexts. The system does not rely on a single hashing standard, but instead provides a multi-algorithm architecture, allowing the user to select the most appropriate function depending on the threat model, performance constraints, and application domain.

🔑 Password Hashing and Key Derivation Functions

These algorithms are specifically designed to resist brute-force and dictionary attacks by introducing computational and/or memory cost.

  • BCRYPT
    BCRYPT is a well-established password hashing function based on the Blowfish cipher. Within Speedcrypt, however, it is not used as a general-purpose password hashing algorithm, but is exclusively employed for SALT processing and strengthening. Its adaptive cost factor and built-in resistance to brute-force attacks make it particularly suitable for reinforcing the entropy and computational weight associated with SALT-related operations.

  • SCRYPT
    Scrypt extends the concept of computational hardness by introducing memory hardness, significantly increasing resistance against GPU, FPGA, and ASIC-based attacks.


Argon2 represents the modern standard for password hashing:

  • Argon2i: optimized against side-channel attacks
  • Argon2d: optimized against GPU cracking attacks
  • Argon2id: hybrid approach, offering balanced protection

These algorithms represent the current state-of-the-art in password-based security.

  • PBKDF2-HASH
    A widely adopted standard based on iterative HMAC operations. While less resistant to parallel attacks compared to modern designs, it remains reliable and highly compatible across systems.


  • SHA-2 (SHA-224, SHA-256, SHA-384, SHA-512)
    These are among the most widely used secure hash functions globally. They provide strong collision resistance and are suitable for general-purpose cryptographic use.

  • SHA-3 (SHA3-256, SHA3-384, SHA3-512)
    Based on the Keccak sponge construction, SHA-3 offers a fundamentally different internal design compared to SHA-2, providing an additional layer of structural diversity.

  • SHAKE-128 / SHAKE-256
    Extendable Output Functions (XOFs) that allow variable-length output, useful in advanced cryptographic constructions.

  • KECCAK (224–256-384-512)
    The original algorithm behind SHA-3, included for compatibility and flexibility in custom implementations.


  • BLAKE-256 / BLAKE-512
    Finalists of the SHA-3 competition, designed for high performance and strong security

  • BLAKE2b / BLAKE2s
    Optimized versions of BLAKE with improved speed and efficiency, widely used in modern applications.

  • BLAKE3 (256–1024)
    A highly parallel and extremely fast hash function, designed for modern multi-core systems. It supports variable output sizes and offers excellent scalability.


  • RIPEMD (128–160-256-320)
    A family of hash functions developed as an alternative to SHA. RIPEMD-160 remains notable for its historical use in cryptographic systems such as blockchain technologies.

🔑 Legacy and Specialized Algorithms

  • MD5
    Now considered cryptographically broken due to collision vulnerabilities. Retained exclusively for compatibility and non-security-critical use cases.

  • TIGER (128/160/192)
    Designed for high-speed hashing on 64-bit systems, historically used in performance-critical applications.

  • WHIRLPOOL
    A hash function based on AES-like transformations, offering strong security and large output size (512-bit).

  • SKEIN (256/512/1024)
    A flexible hash function based on the Threefish cipher, designed for high performance and configurability.


HMAC (Hash-based Message Authentication Code) combines a hash function with a secret key to provide integrity and authenticity:

  • HMACSHA1
  • HMACMD5
  • HMACSHA-256 / 384 / 512
  • HMACRIPEMD-160

Within Speedcrypt, the HMAC family is not used as a simple authentication primitive, but as a Key Derivation Function (KDF) mechanism.
HMAC-based constructions are used as building blocks for key derivation processes, ensuring controlled and secure expansion of input keying material.
This approach provides:

  • Strong resistance to length extension attacks
  • Controlled and repeatable key derivation
  • High compatibility with established standards (e.g., PBKDF2)

🔑 International Cryptographic Standards

Speedcrypt explicitly includes algorithms from multiple geopolitical standards, ensuring global applicability and compliance.

🔑 Russian Federation Standards


These algorithms are officially standardized in the Russian Federation and are designed with strong cryptographic properties, including resistance to modern attack vectors. They represent a robust and well-engineered alternative to widely adopted Western standards.

🔑 People’s Republic of China Standard


SM3 is a cryptographic hash function standardized in China, widely used in governmental and commercial applications. It offers security properties comparable to SHA-256 and is designed to meet national regulatory requirements.

🖊️Implementation Notes and Internal Usage

Within Speedcrypt, hashing algorithms are not only exposed as selectable primitives, but are also assigned precise internal roles to ensure consistency, security, and correct usage.

  • BCRYPT → SALT strengthening and handling
  • HMAC → deterministic and secure key derivation (KDF)

This separation is intentional and enforces strict control over how cryptographic primitives are used within the system.

🖊️ Engineering Perspective

The inclusion of this extensive set of hashing algorithms is a deliberate design choice based on:

  • Security Diversity: Avoid reliance on a single cryptographic primitive
  • Performance Adaptability: Select algorithms optimized for specific hardware
  • Backward Compatibility: Maintain support for legacy systems
  • Regulatory Compliance: Enable usage across different national frameworks

🖊️Final Consideration

I am particularly pleased to present the inclusion of cryptographic algorithms standardized by the Russian Federation and the People’s Republic of China. These algorithms—such as STREEBOG and SM3—are often underestimated or overlooked in Western-centric implementations, yet they are the result of rigorous engineering processes and represent highly valid, robust, and secure cryptographic solutions. Their presence within Speedcrypt is not only a matter of completeness, but a conscious recognition of their technical value and their importance in ensuring true global interoperability and compliance.
Protection Against Dictionary Attacks
✒️ Key Derivation Functions and Resistance to Attakcs

Speedcrypt provides robust protection against a variety of common attack vectors, including dictionary attacks, brute-force attempts, and rainbow table attacks. While no system can offer absolute immunity, these threats can be substantially mitigated by properly deriving the Master Key using a securely generated SALT, which introduces computational and temporal barriers designed to prevent pre-computation and significantly increase the effort required for unauthorized key recovery. The system exposes a suite of advanced Key Derivation Functions (KDFs), each with distinct characteristics and defense profiles:

  • Argon2id:
    Among the Argon2 family variants, Argon2id is preferred for balancing resistance to side-channel attacks with performance. It is particularly effective against attacks leveraging GPU or ASIC hardware, thanks to its memory-hard design and controlled parallelism. This ensures that Master Key derivation remains secure even in environments where high-performance hardware could otherwise compromise weaker algorithms.

  • Scrypt:
    Scrypt is a memory-intensive KDF specifically designed to resist modern high-efficiency password cracking techniques, including GPU, FPGA, and ASIC-based attacks. By enforcing substantial memory usage alongside computational cost, Scrypt significantly increases the complexity and resource requirements for any attempt to guess the Master Key or derived encryption keys.

  • PBKDF2:
    A widely recognized standard (RFC 2898), PBKDF2 employs iterative HMAC-based transformations to resist dictionary and rainbow table attacks. Its strength derives from configurable iteration counts, allowing a controlled trade-off between performance and security. While not specifically designed to resist highly parallel GPU attacks, PBKDF2 remains a reliable and well-established choice in many standard environments.

All KDFs in Speedcrypt are designed to integrate seamlessly with securely generated SALTs, ensuring that each derivation produces unique cryptographic keys, even when identical passwords are used. This property significantly increases the computational workload required for attackers attempting pre-computation or reuse of known hashes. Importantly, the principles underlying Argon2id, Scrypt, and PBKDF2 are extensible to all hashing and key transformation functions within Speedcrypt. The system enables users to tailor the derivation strategy according to hardware capabilities, operational context, and security requirements, ensuring a flexible yet rigorous defensive posture.
By combining memory-hard designs, computational cost, and cryptographically secure random SALTs, Speedcrypt maximizes resistance against a broad spectrum of attack vectors. This approach reflects an engineering-driven commitment to safeguarding sensitive data, while providing users with the tools necessary to optimize security based on their specific environment.

🖊️Technical Note on SALT

In the context of the Speedcrypt project, the term SALT refers to a random value appended to the password or Master Key to enhance resistance against dictionary, brute-force, and rainbow table attacks. This value is fundamental in ensuring that each key derivation is unique, making it extremely difficult for an attacker to pre-compute values or replicate cryptographic transformations. It is important to note that the term SALT is widely used in cryptography with this specific meaning, while in other areas of computer science it may refer to different concepts or internal structures. In the context of Speedcrypt, however, SALT always refers to this cryptographic protection mechanism, and every mention of SALT in this guide pertains exclusively to this function.
Secure Deletion
✒️ Secure File Erasure Algoritms in Speedcrypt

Speedcrypt integrates a comprehensive set of secure file erasure algorithms designed to mitigate data remanence and prevent recovery of sensitive information from storage media. These algorithms operate by overwriting the target data with deterministic or random patterns across one or multiple passes, ensuring that previously stored information cannot be reconstructed using conventional or advanced recovery techniques. The available methods include both modern standards and legacy multi-pass techniques, allowing users to select the most appropriate strategy based on their operational context.

🗑️Single-Pass Methods

🖌️ Quick 1 Pass

     Performs a single overwrite pass using a fixed pattern (typically zeros or a predefined value).

  • Fast execution
  • Suitable for non-critical scenarios
  • Limited resistance against advanced forensic techniques on legacy media

🖌️ Random 1 Pass

    Executes a single overwrite using cryptographically secure random data.

  • More robust than fixed-pattern overwrite
  • Considered sufficient for modern storage devices in many real-world scenarios
  • Recommended baseline for performance/security balance

🗑️ Multi-Pass Standard Algorithms

🖌️ DoD 3 Passes / DoD 7 Passes

    Based on historical U.S. Department of Defense practices.

  • Multiple overwriting passes with alternating patterns
  • Designed for magnetic media
  • Today considered largely superseded, but still used in regulated environments

🖌️ Scheneier 7 Passes

    Proposed by Bruce Schneier.

  • Combines deterministic and random overwrites
  • Aims to address residual magnetic traces
  • Primarily relevant for legacy storage technologies

🖌️ German VSITR 7 Passes

    German government standard for secure deletion.

  • Structured overwrite sequences
  • Designed for high-assurance environments
  • Similar considerations as other multi-pass methods

🖌️ Gutmann 35 Passes

    Developed by Peter Gutmann.

  • Extensive multi-pass overwrite scheme targeting multiple encoding methods
  • Historically significant but largely excessive for modern drives
  • High computational cost with limited practical advantage today

🗑️ Government and Institutional Standards

🖌️ RCMP TSSIT OPS-II

    Canadian standard for secure data destruction.

  • Multi-pass overwrite with defined patterns
  • Intended for sensitive governmental data

🖌️ British HMG IS5 [Enhanced]

    United Kingdom government standard.

  • Enhanced multi-pass scheme
  • Designed for classified or restricted information

🖌️ NSA/CSS Standard 9 / 12

     Associated with U.S. intelligence community practices.

  • High number of overwrite passes
  • Focus on maximum data sanitization assurance

🖌️ NIST 800-88 Rev.1 Secure Erase

       Based on National Institute of Standards and Technology guidelines.

  • Represents modern best practices for media sanitization
  • Emphasizes effectiveness over excessive pass count
  • Recognizes that for modern storage, properly executed overwrite or device-level erase is sufficient

🗑️ Generic and Adaptive Methods

🖌️ Secure Delete

       General-purpose secure erasure method.

  • Typically combines random overwriting with verification
  • Balanced approach for everyday secure deletion

🗑️ Custom Erasure Strategy


    This method provides a fully configurable erasure strategy defined by the user.

     From an engineering perspective, this represents a parametric sanitization model, allowing control over:

  • Number of overwrite passes
  • Pattern composition (fixed, random, hybrid)
  • Execution sequence
  • Potential verification steps

This flexibility enables adaptation to:

  • Specific threat models
  • Regulatory requirements
  • Hardware characteristics
  • Performance constraints

When correctly configured, this approach can match or exceed the effectiveness of predefined algorithms, while avoiding unnecessary overhead.

🖊️Engineering Considerations

It is important to clarify that:

  • Modern storage devices (SSD, NVMe) do not behave like traditional magnetic disks
  • Multi-pass overwriting does not necessarily provide additional security on such devices
  • Device-level secure erase commands are often more effective

Therefore, the selection of an erasure algorithm should be based on:

  • Storage technology (HDD vs SSD)
  • Sensitivity of the data
  • Operational constraints
  • Required assurance level

🖊️Final Consideration

Speedcrypt does not impose a single erasure strategy, but provides a complete and flexible framework.
Security is not determined by the number of passes alone, but by:

  • Correct algorithm selection
  • Proper execution
  • Alignment with the actual threat model

In this context, Speedcrypt enables both high-assurance sanitization and efficient real-world operation, maintaining a rigorous engineering approach to data destruction.
Process Memory Protection
✒️ In-Memory Protection of Sensitive Data

Speedcrypt implements a strict in-memory protection model to safeguard highly sensitive data, specifically the Master Key and its associated SALT, ensuring that plaintext exposure is minimized both in duration and scope. At no point are critical cryptographic assets retained in unprotected memory longer than strictly necessary. All sensitive data is stored in an encrypted form within the process address space, significantly reducing the risk of extraction through memory inspection tools, process dumps, or debugging techniques.

💻 Memory Encryption Mechanism

The protection of in-memory data is enforced through the use of the Windows Data Protection API (DPAPI), specifically via the ProtectedMemory feature. This mechanism provides:

  • Encryption keys managed internally by the operating system
  • Storage of keys in a secure, non-exportable memory region
  • Binding of encryption context to the current user and machine

As a result:

  • Encrypted data cannot be decrypted outside the originating system context
  • Access to process memory alone is insufficient to recover sensitive information
  • Even privileged attackers face significant barriers without full system compromise

This approach leverages a mature and widely validated security infrastructure available on Windows platforms starting from legacy systems up to modern environments.

💻 Controlled Plaintext Exposure

Certain cryptographic operations require temporary access to plaintext data. Speedcrypt enforces strict control over these scenarios through a tightly bounded lifecycle:

🚀 Temporary Unencrypted Buffering
       Sensitive data (Master Key and SALT) is loaded into byte arrays exclusively for the duration of the required operation.

🚀 Immediate Re-Encryption
       As soon as the operation is completed, the data is re-encrypted using DPAPI and returned to protected memory.

🚀 Secure Memory Sanitization
       All buffers that previously contained plaintext data are explicitly overwritten using zeroed or randomized patterns before being released, preventing residual data recovery.

This lifecycle ensures that plaintext exposure is:

  • Short-lived
  • Explicitly controlled
  • Immediately mitigated after use

💻 Runtime Limitations and Mitigations

It is acknowledged that the Windows operating system and the .NET runtime may create implicit memory copies during internal operations, such as:

  • String handling
  • Buffer resizing
  • Garbage collection processes

These memory regions are managed outside the direct control of the application and cannot be deterministically sanitized.
To mitigate this inherent limitation, Speedcrypt:

  • Avoids unnecessary use of immutable strings for sensitive data
  • Prefers controlled byte array handling
  • Minimizes the lifetime of plaintext data
  • Ensures deterministic sanitization of all explicitly allocated buffers

💻 Layered Memory Defense Model

The in-memory protection strategy of Speedcrypt is based on multiple coordinated layers:

  • Encrypted Process Memory prevents direct extraction of sensitive data
  • Controlled Plaintext Lifecycle minimizes exposure during operations
  • Explicit Memory Overwriting mitigates forensic recovery risks
  • System-Level Key Protection (DPAPI) isolates cryptographic keys from application space

🖊️Engineering Conclusion

This model ensures that sensitive cryptographic material remains protected even under advanced attack scenarios involving memory inspection or process analysis. While no software-based approach can completely eliminate all memory-related risks—especially in the presence of full system compromise—Speedcrypt reduces the attack surface to well-defined and controlled conditions. The combination of operating system–level protection, strict memory handling discipline, and proactive sanitization establishes a robust and realistic defense against memory-based attacks, without compromising the efficiency and reliability of cryptographic operations.
Self-Test
✒️ Self-Test Module Overview

The Self-Test module represents a fundamental engineering component within Speedcrypt, designed to ensure the reliability, consistency, and operational integrity of the entire system. At startup, Speedcrypt performs an automatic diagnostic process that validates both encryption engines and hash functions. Compared to previous versions, this mechanism has been significantly enhanced in terms of performance and efficiency. The system is capable of executing 44 distinct tests within approximately three to four seconds, a result that reflects careful optimization and a highly efficient internal architecture.

This execution time is intentionally kept low to avoid impacting the overall startup experience while still providing a comprehensive verification layer. The Self-Test module is not limited to a superficial validation. It verifies the correct behavior of cryptographic primitives, checks internal consistency, and ensures that all critical components operate within expected parameters before they are made available to the user. This approach minimizes the risk of silent failures and guarantees that the system starts in a known, trusted state. From an engineering perspective, the Self-Test acts as a preventive control layer, allowing Speedcrypt to detect anomalies, misconfigurations, or potential integrity issues at the earliest possible stage. For more detailed information about the Self-Test procedures and their internal structure, please refer to the dedicated page in this site.
Other Security Options
✒️ Other Security options

Speedcrypt integrates a set of advanced security mechanisms designed to operate alongside the core cryptographic modules, providing continuous integrity verification, anti-tampering protection, and runtime data safeguarding. These components are engineered as independent control layers, ensuring that the overall system remains reliable, resistant to manipulation, and secure even under adverse conditions.

🪛 Self-Test of Configuration File

Speedcrypt performs a continuous integrity self-test on its configuration file, treating it as a critical security asset. The system verifies both structural consistency and cryptographic integrity, allowing it to detect:

  • Unauthorized modifications
  • Data corruption
  • Inconsistent or malformed configuration states

Any discrepancy immediately triggers a security alert and prevents the execution of sensitive operations until the configuration integrity is fully restored. This proactive mechanism ensures that all project parameters remain trusted, consistent, and resistant to tampering, eliminating the risk of operating under compromised settings.

🔧 Self-Test of the Utility Tool

The Utility Tool is an independent module responsible for auxiliary but sensitive operations, including:

  • Association of project-specific icons with encrypted files
  • Backup and restore of protected project data

Before any interaction with the main encryption engine, Speedcrypt performs a dedicated self-test on this module to verify:

  • Binary integrity
  • Functional correctness
  • Operational consistency

This guarantees that every operation executed through the Utility Tool is reliable, deterministic, and free from compromise, preventing indirect attack vectors through auxiliary components.

🔨 Self-Test for Anti-Tampering of Sensitive Files

All sensitive files managed by Speedcrypt are subject to periodic anti-tampering self-tests.
These routines validate:

  • Cryptographic hashes
  • File metadata
  • Structural integrity

Any detected anomaly—whether caused by corruption or unauthorized modification—triggers an immediate alert and blocks the use of the affected file in any cryptographic operation. This approach effectively mitigates the risk of silent tampering attacks, ensuring that no compromised data is ever processed by the encryption or decryption engines.

🖥️ Print Screen Obfuscation

During critical operations, Speedcrypt actively protects sensitive visual data by intercepting screen capture attempts.
When a screenshot is triggered:

  • Sensitive information is automatically obfuscated
  • Or replaced with protected placeholders

This mechanism operates transparently with standard Windows capture utilities while ensuring that confidential data cannot be exposed through screen acquisition techniques. From a security standpoint, this represents a runtime data protection layer, specifically designed to prevent visual exfiltration of sensitive information.

🖊️Engineering Perspective

These security options are not auxiliary features, but integral parts of a defense-in-depth strategy.
By combining:

  • Continuous self-testing
  • Independent module verification
  • Anti-tampering controls
  • Runtime data protection

Speedcrypt ensures that security is enforced not only at the algorithmic level, but across the entire operational lifecycle of the system.

🖊️Security Correlation note

This section defines the formal correlation between identified threat scenarios and the security mechanisms implemented in Speedcrypt. Each countermeasure operates as an independent control layer within a defense-in-depth architecture, ensuring that no single failure can compromise the overall security of the system.

📖 Threat → Countermeasure Mapping:
💻 Threat Scenario
🕵️‍♀️ Attack Description
🛠️ Countermeasure😎 Security Effect😧 Residual Risk
Configuration Tampering
Unauthorized modification of configuration parameters
Self-Test of Configuration FileBlocks execution under compromised configurationRequires OS-level compromise to bypass
Configuration Corruption
Accidental or induced corruption of configuration data
Continuous integrity verification
Ensures only valid configuration states are accepted
Minimal, limited to catastrophic hardware faults
Utility Tool Compromise
Tampering or replacement of auxiliary module binaries
Self-Test of the Utility Tool
Prevents indirect compromise through external modules
Possible only with full system compromise
Sensitive File Tampering
Unauthorized modification of protected files
Anti-Tampering Self-Test for Sensitive Files
Prevents usage of compromised data
Limited to undetected low-level disk manipulation
Silent Data Manipulation
Undetected alteration of cryptographic material
Hash and metadata validation
Guarantees data integrity before processing
Negligible with strong hash algorithms
Screenshot Data Leakage
Capture of sensitive data via screen acquisition
Print Screen Obfuscation
Prevents visual exfiltration of confidential data
External camera or hardware capture remains possible
Runtime Data Exposure
Leakage of sensitive data during execution
Runtime protection mechanisms
Reduces exposure of sensitive information in memory
Advanced memory scraping attacks on compromised systems
Precomputation Attacks
Use of rainbow tables or precomputed hashes
SALT reinforced with Bcrypt
Eliminates effectiveness of precomputed attacks
None if SALT is unique and properly generated
Brute Force Attacks
Exhaustive password/key guessing attempts
HMAC-based KDF
Increases computational cost and attack resistance
Dependent on password strength and iteration count
Weak Entropy
Predictable or insufficient randomness
Secure PRNG mechanisms
Ensures high-quality entropy for cryptographic operations
System entropy source compromise
Module Integrity Failure
Malfunction or inconsistency in internal components
Startup Self-Test
Guarantees trusted operational state before execution
Runtime failures after initialization
🖊️Engineering Conclusion

This correlation model demonstrates that Speedcrypt enforces security through multiple independent and complementary layers:

  • Detection through continuous self-testing and integrity verification
  • Prevention by blocking execution in untrusted or inconsistent states
  • Protection via runtime safeguards and data obfuscation mechanisms

The introduction of residual risk analysis highlights that no system can be considered absolutely secure, but confirms that Speedcrypt reduces all identified threats to controlled and well-defined conditions. Each protection mechanism is deliberately designed to operate both independently and in coordination with others, ensuring that even in the presence of partial failures, the system maintains a secure and predictable behavior.

🖊️Trust & Assumptions Model

To provide a clear engineering context, Speedcrypt explicitly defines the assumptions and trust boundaries under which the system operates:

⚙️ Assumptions

  • The operating system is considered reliable but may be subject to vulnerabilities.
  • Attackers may have access to files on disk or attempt offline brute-force attacks.
  • Memory may be observed under advanced threat scenarios.
  • Users follow recommended security practices for password and key management.

⚙️ Trust Model

  • Files on disk are not trusted; integrity is continuously verified.
  • Auxiliary modules, including the Utility Tool, are verified via self-tests before operation.
  • System state is continuously validated to prevent execution under inconsistent conditions.
  • Only verified and integrity-checked data is used in encryption, decryption, and key derivation processes.

This model ensures that the security design is explicit, auditable, and realistic. It clarifies which components can be assumed trustworthy, which require verification, and where residual risk remains. By defining these boundaries, Speedcrypt establishes a professional, engineering-driven foundation for all cryptographic and operational guarantees.
Security Questions
✒️ Security Questions – Engineering Perspective

During the period related to the functional tests of the Speedcrypt Project, several questions were raised by users who were completely unfamiliar with cryptography and data security. These questions are extremely relevant because they highlight common misconceptions about how security mechanisms actually work. Below are some of the most significant ones:

  • Encrypting already encrypted files multiple times would not necessarily increase security and prevent modifications by a malicious program?
  • Encrypting backup archives would increase security by preventing modifications by a malicious program?
  • Encrypting the Speedcrypt executable file, folder content, and backup files would increase security by preventing modifications by a malicious program?

🔐On Multiple Encryption (Double / Cascade Encryption)

To the first question, the answer is that encrypting files multiple times, commonly referred to as Double Encryption or Cascade Encryption, is generally not recommended in practical systems. While, in theory, multiple independent encryption layers could increase resistance against certain classes of cryptanalysis, in real-world implementations this approach introduces critical drawbacks:

  • Increased architectural complexity
  • Higher probability of implementation errors
  • More difficult key management
  • Risk of incorrect or insecure chaining of algorithms

Security, in modern cryptographic engineering, is not achieved by stacking layers indiscriminately, but by applying a single, strong, well-designed algorithm, combined with:

  • High-entropy keys
  • Robust key derivation mechanisms
  • Correct implementation

For this reason, repeatedly encrypting already encrypted data does not represent a valid or necessary security enhancement within the Speedcrypt model.

🔑 On Encrypting Backups, Executables, and Data Structures

As for the remaining two questions, the answer is unequivocal: NO!
Applying encryption to backup archives, executable files, or working directories does not provide protection against malicious modification if the system itself is compromised. This misconception arises from confusing confidentiality with system integrity and trust.

Encryption protects data from unauthorized reading, but it does not:

  • Prevent modification by privileged processes
  • Stop code injection or execution tampering
  • Protect against runtime interception
  • Guarantee integrity of the execution environment

Speedcrypt is designed to provide strong protection against multiple classes of attack vectors, both at input acquisition level and during runtime execution, including:

  • Keyloggers
  • Master Key monitoring
  • Dictionary and brute-force attacks
  • Memory dump and inspection attacks
  • Padding Oracle attacks, mitigated through correct cryptographic design and secure error handling, preventing any leakage of information about the encryption process
  • Data tampering and integrity manipulation attempts

However, these protections operate under a fundamental assumption: the execution environment is trusted. If a malicious program specifically designed to target software like Speedcrypt is present on the system, these protections become ineffective.

📚 Fundamental Security Law (Non-Negotiable Constraint)

This limitation is not specific to Speedcrypt, but is formally defined in Law #1 of the Ten Immutable Laws of Security, published by Microsoft within the Microsoft TechNet security framework.
Further elaborated in the article “Revisiting the 10 Immutable Laws of Security, Part 1”, the principle is stated as follows:

“If a bad guy can persuade you to run his program on your computer, it's not your computer anymore!”

From an engineering standpoint, this is a hard boundary condition:

  • If an attacker achieves code execution on the system
  • The trust model collapses entirely
  • Any application-level protection becomes irrelevant

This means that:

  • Encryption cannot protect data during execution in a compromised environment
  • No software, including Speedcrypt, can guarantee security under these conditions
  • Additional “protective” measures such as encrypting files, backups, or executables do not mitigate this risk

✍️ Operational Security Guidelines

To avoid scenarios like the one described above, it is essential to follow strict operational rules. Security is not achieved by a single mechanism, but by the correct behavior of the entire system and its user.

🖥️ Your System

  • When operating on Windows 10 or later, rely on the built-in antivirus solution (Microsoft Defender), ensuring it is properly configured with maximum protection settings
  • Keep the system firewall enabled and correctly configured at all times
  • Apply all available security updates and patches regularly
  • Never open attachments from unknown sources or messages that impersonate transport companies, banks, or financial institutions
  • Prefer browsing trusted, certified, and secure websites
  • Do not download or install software from untrusted or unverifiable sources

🗝️ With Speedcrypt

  • Always verify all input data before processing, including Master Keys and file lists
  • Entering unverified data may lead to sensitive data exposure or execution of malicious content
  • Always use highly complex Master Keys; Speedcrypt allows secure storage of such keys in dedicated files
  • Never accept suggestions to weaken key transformation parameters, as this directly facilitates cryptographic attacks
  • Avoid using password generators proposed by untrusted entities, as they may produce predictable or compromised keys
  • hen handling encrypted files from external users, exercise extreme caution; decrypted content may be malicious
  • Regularly perform a full Self-Test of the cryptographic algorithms to ensure integrity and correctness

🖊️Final Consideration

It is essential to understand that all the attack scenarios described above share a common prerequisite: user involvement.
An attacker cannot:

  • Execute malicious code
  • Alter configurations
  • Introduce compromised data

without some form of user interaction, whether direct or indirect. For this reason, security must be considered a shared responsibility between system design and user behavior. If the rules described above are strictly followed and operational sessions are conducted with full awareness, the effectiveness of these attack vectors is drastically reduced.
In other words, an attacker always requires your unwitting complicity. Without it, these attacks cannot be successfully executed.
On the subject of safety with the Speedcrypt Project, that’s all for now. Follow these tips carefully and consult high-quality texts and serious sites on the subject. Set the right strategy to achieve great results and keep your data secure!
Back to content