Encryption clarifications

Started by: Ciberyan on

Ciberyan
Post #1 -
Encryption clarifications

Hello Vlad
I post here as may be the answer can help others to also understand better
My question is about security, I would like to be sure to understand right
As you say : "AllMyNotes Organizer secures the database using AES-256 for the key and ChaCha22 for all stored content."
At first I dont find anything on Chacha22 but Chacha20, may be a typo ?
Then, if we dont give a password, is this mean that the key is not encrypted ?
The two layer of encryption is not easy to understand for the non specialist ...
and at last for a maximum security, can we choose our own key for encrption ?
Thanks in advance
Fred, France

Vlad Frytskyy
Post #2 -

Hello Fred,

Thanks for asking this publicly. Others will find it useful too.

1. ChaCha22?

Guilty. ChaCha22 doesn't exist. Not yet, anyway; give the cryptographers a few years. It's ChaCha20, the well-known modern cipher also used in TLS, WireGuard and Chrome. Our encryption is considerably more precise than our typing, I promise. Thanks for spotting it!

2. Two layers, explained simply

Think of a safe inside a locked room:

  • Your notes are encrypted with ChaCha20 using a random 256-bit key. Each database file gets its own key, generated automatically when the file is created. Nobody chooses it, nobody knows it, not even us, and it's never the same for two files.
  • That key is then locked with AES-256 using your password. Your password goes through 600,000 rounds of hardening (PBKDF2-SHA256) first, so anyone trying to guess it by brute force should pack a lunch. And probably a retirement plan.

Why two layers? Your notes are protected by a truly random key, not directly by a password a human chose (we've seen the passwords humans choose). It also lets us manage the key separately from the data, as described below.

3. What if I don't set a password?

Your notes are still encrypted, but the key is then locked with a built-in app key, which isn't secret. So it stops casual snooping (you can't read the file in a text editor or a disk viewer), but anyone who has your file and a copy of AllMyNotes can open it. Think of it as a front door locked with the key under the doormat: perfectly secure, as long as nobody checks under the doormat. For real protection, please set a password. It's the one thing that actually keeps your data private.

4. Can I choose my own encryption key?

No, and that's on purpose. A random 256-bit key from a cryptographic generator is far stronger than anything a person would pick. Experience shows that "user-chosen encryption key" tends to mean "qwerty123" or the cat's birthday. Your password is your personal key. Make it long and unique. Yes, the cat's birthday is out.

What you can do is get a new random key whenever you want, which is what really matters:

  • Automatically: every time you set, change or remove your password, AllMyNotes generates a brand-new key and re-encrypts all your data with it. This also happens when you upgrade an older database to the new format.
  • On demand: File > Storage File Details... > Regenerate encryption key... gives you a fresh key while keeping your current password.

Why do we bother? Many encryption tools only re-lock the existing key when you change your password, because it's faster, and "military-grade encryption" looks just as good on the box either way. The weakness is that if someone ever got hold of that key, for example by copying the file while it had no password or a weak one, a stolen copy of the key would keep working even after you switch to a strong password. Changing the lock while the burglar keeps a copy of the old key: very comforting, not very useful. In AllMyNotes, a new password always means a new key, so anything taken earlier becomes useless for your current data. The button covers the remaining case: you're happy with your password but want a fresh key anyway, out of caution, healthy paranoia, or plain routine hygiene.

One natural limit: old copies and backups made before the change still open with the old password. We're good, but we can't reach into a USB stick in your drawer. After a password change, AllMyNotes offers to clean up old backups for you.

A note on versions
All of this is new in AllMyNotes 5.03, which is currently in beta. We've only just released it, and the new file format is exactly what we're testing right now. So far everything is going smoothly, with no surprises, which in software is itself a little suspicious. Before release we tested it very thoroughly: thousands of automated test cases covering the trickiest scenarios, including aggressive concurrent changes in multithreaded mode. Basically, we tortured it so you don't have to.

Earlier versions used somewhat different algorithms. They served users well, with no known breaches in 17 years. Hackers had plenty of time, and apparently better things to do. But security standards keep moving and we wanted to stay well ahead. When you open an older database in 5.03, the app will offer to upgrade it to the new format.

Best regards,
Vlad

Post Reply

📝 Anonymous posting: Your message will be reviewed by moderators before appearing publicly.
Formatting: [b]bold[/b] [i]italic[/i] [u]underline[/u] [url]link[/url] [quote]text[/quote] [code]code[/code] [img]url[/img] [list][*]item[/list] — Preview
Please answer "NO" to have your message delivered!

🛡️ Vladonai Secure Community Platform [BETA]

Powered by Vladonai Minimalistic Forum Script | Designed for AllMyNotes Organizer Community

🔐 Login via Dashboard for full forum privileges

© 2026 Vladonai Software | AllMyNotes Organizer Community