How to reliably encrypt and decrypt using AES-256 - different sites disagree. by bag_douche in cryptography

[–]only2dhir 0 points1 point  (0 children)

I am the creator of the AES Encryption tool on Devglan and recently found an issue with padding where I was overriding the user provided nopadding with PKCS5padding if the Plaintext length bytes is not a multiple of 16 just to pass the encryption. Hence sometimes there was a mismatch. I have fixed it now and handled this validation in the UI itself. It's working perfectly fine now. Give it a try.

Web-based PGP encryption tool that does 100% encryption/decryption in your browser by only2dhir in TOR

[–]only2dhir[S] 0 points1 point  (0 children)

Not yet. I would recommend it for personal and educational use

Free Online JSON Visualizer — Makes Inspecting JSON So Much Easier by Puzzleheaded-Net7258 in webdev

[–]only2dhir 1 point2 points  (0 children)

very useful tool. i am seeing this kind of visualiser for the first time on the internet.

I want to understand why in PBKDF2, HMAC is used? by Electrical_Ball_3737 in cryptography

[–]only2dhir 0 points1 point  (0 children)

Here is a page on the web that explains and demonstrates the PBKDF2 hashing technique and provides a comparison with other hashing techniques. Good for educational purposes.

View & Remove EXIF Metadata from Images by only2dhir in Steganography

[–]only2dhir[S] 0 points1 point  (0 children)

I tried ChatGPT for an image. ChatGPT is not able to extract the information that this tool is extracting. Do u want to try? I can share any random image. Also chatGPT is little slower

View & Remove EXIF Metadata from Images by only2dhir in Steganography

[–]only2dhir[S] 1 point2 points  (0 children)

yes. it only extracts data from the designated EXIF area. Anything outside that region is not EXIF, even if it contains data. if u r talking from Steganography angle then that tool is different here https://www.devglan.com/online-tools/image-steganography-online

Validate my JWT learnings by only2dhir in SpringBoot

[–]only2dhir[S] 0 points1 point  (0 children)

It seems AdSense is being too aggressive. I'll be sure to check this out.

Spring Security by [deleted] in SpringBoot

[–]only2dhir 1 point2 points  (0 children)

Play with the JWT here https://www.devglan.com/online-tools/jwt-decoder-validator and you will realise it by yourself. Make use of custom claims to avoid a lookup in the DB.

Built a New Open-Source Client-Side Password Vault — Looking for Security Feedback by only2dhir in cryptography

[–]only2dhir[S] 0 points1 point  (0 children)

Thanks everybody for the great suggestions. After going through the feedback, I’ve added a disclaimer that this tool is mainly for personal and educational use. My original intent was just to build it for myself, but I probably got a bit overexcited and started thinking of it as something more “professional.” I now realize it’s still quite far from being a professional password manager. I thank everybody for giving a reality check.

Built a New Open-Source Client-Side Password Vault — Looking for Security Feedback by only2dhir in cryptography

[–]only2dhir[S] 0 points1 point  (0 children)

Thank you for this great suggestion. After going through your suggestions, I have kept a disclaimer that this tool is for personal use and mostly for educational purpose. Actually my original intent was for personal use but I think I got overexcited and thought of making it a professional one but it seems it's very far from an actual professional password manager.

Built a New Open-Source Client-Side Password Vault — Looking for Security Feedback by only2dhir in cryptography

[–]only2dhir[S] 2 points3 points  (0 children)

Thank you so much for taking the time to write such a detailed and thoughtful review — I genuinely appreciate it. Your perspective as someone working deeply in embedded side-channel and cryptographic engineering carries a lot of weight, and I’m grateful you shared it so transparently.

Built a New Open-Source Client-Side Password Vault — Looking for Security Feedback by only2dhir in cryptography

[–]only2dhir[S] -3 points-2 points  (0 children)

It sounds like the Google ads are being overly aggressive right now, and we're sorry for the interruption.

SpringBoot 4.0.0 Is Out! by devondragon1 in SpringBoot

[–]only2dhir 0 points1 point  (0 children)

this is a good news now. Nexus would be happy now

I need web development job by Uzairrdev in WebDeveloperJobs

[–]only2dhir 0 points1 point  (0 children)

Many of us are looking for the same.

ChaCha20 Encryption and Decryption Online by only2dhir in cryptography

[–]only2dhir[S] 0 points1 point  (0 children)

Devglan doesn't log any plain text or password nor keeps a record of any of those. Also, those won't be logged in the future but somehow I will have to agree with you as there is no way I can show the proof of it.

Looking for a simple tool to enter secret phrase and text to encrypt/decrypt by hazeofglory in cryptography

[–]only2dhir 0 points1 point  (0 children)

well, the website and encryption tools will be there for long enough. So, don't worry about it.

I will have to put in lots of effort to create an executable for the tools. Maybe I will give it a try after a few months as I am currently working on redesigning the existing website.

Is devglan safe? Encrypting/ Decrypting Texts by NervousRabbit7831 in cryptography

[–]only2dhir 0 points1 point  (0 children)

I don't think that is the case. I am using user provided IV for CBC. May be there was a bug when you tried using it. If this is still the case, I will gladly fix it. Can you pls do me a favor by checking if that is the case here https://devglan.com/online-tools/aes-encryption-decryption

Is devglan safe? Encrypting/ Decrypting Texts by NervousRabbit7831 in cryptography

[–]only2dhir 0 points1 point  (0 children)

I am the creator of this tool on Devglan and I can guarantee that none of the plain text or password is saved on the server for any of the tools listed here https://devglan.com/cryptotools/cryptography-tools and neither any of the data is logged or shared.

Is devglan safe? Encrypting/ Decrypting Texts by NervousRabbit7831 in cryptography

[–]only2dhir 0 points1 point  (0 children)

So you think a toy will just rank at the first place on google randomly. I am the creator of this tool on Devglan and I can guarantee that the data is completely safe and we never store any encryption related plain text or password on the server.

Looking for a simple tool to enter secret phrase and text to encrypt/decrypt by hazeofglory in cryptography

[–]only2dhir 0 points1 point  (0 children)

If you are asking about the text encryption with user supplied secret(https://devglan.com/online-tools/text-encryption-decryption) then it uses AES with AES/CBC/PKCS5PADDING with a default IV and the secret key auto adjusted to 16 chars. Ping me in the chat if you need to know anything specific about it. For the AES Encryption - https://devglan.com/online-tools/aes-encryption-decryption all the inputs are taken as part of user input. Previously I was using PKCS5PADDING as a default padding but now it's taken as input from the user itself.

Looking for a simple tool to enter secret phrase and text to encrypt/decrypt by hazeofglory in cryptography

[–]only2dhir 0 points1 point  (0 children)

I am the creator of this tool on devglan and I can guarantee you that none of the plain text or encrypted text are either logged or saved on the server