Skip to main content

Glyph-based file obfuscation with intentional access control

Project description

Glyphlock

This module contains a simple implementation of glyph-based file obfuscation with optional access control.


What glyphlock does

Glyphlock converts a file into a deterministic representation made up of Unicode Egyptian hieroglyphs.

The original file:

  • is removed
  • is replaced with a .glyph file
  • is no longer readable as plain text

The transformation is fully reversible and does not modify the original data.


What glyphlock is for

Glyphlock is meant to prevent accidental or casual access to files.

It is designed to be used when:

  • files should not be readable at a glance
  • sensitive data should not be opened unintentionally
  • projects need to be parked safely on disk
  • access should require intent

This tool is not encryption and is not designed to protect against determined offline attacks.


Access control

Glyphlock supports optional access gating.

When enabled:

  • a password is required to decode files
  • passwords are verified using a key derivation function
  • passwords are never stored directly

An optional recovery key can also be generated.

The recovery key:

  • is shown once
  • is stored as a hash
  • can be used if the password is lost

If both the password and recovery key are lost, the file cannot be recovered.

Currently Glyphlock allows for a user to create an empty password. If the user does so they must press 'Enter' when prompted for the password.


File behavior

When encoding:

  • the original file is replaced with filename.glyph
  • the original file extension is stored in the header
  • file permissions are preserved
  • the file payload is checksummed

When decoding:

  • the original file is restored exactly
  • permissions are restored
  • corrupted or modified files fail to decode

All file operations use atomic replacement to minimize the risk of data loss.


Directory handling

When operating on directories, glyphlock walks the directory tree recursively.

The following are skipped automatically:

  • symbolic links
  • hidden directories
  • version control metadata (.git, .hg, .svn)
  • virtual environments (.venv, env)
  • Python cache directories (__pycache__)
  • editor configuration directories

Only user-authored files are processed by default.


How to use this module

Glyphlock is used as a command-line tool. Only the encode and encode-directory commands accept access flags. All commands accept --plan flags.

Encode a single file:

glyphlock encode file.txt

Decode a file (decode commands do not accept access flags):

glyphlock decode file.glyph

Encode a directory with a password and recovery key:

glyphlock encode-dir project --lock --recovery

Decode a directory (decode commands do not accept access flags):

glyphlock decode-dir project

Access flags

The following flags are supported when encoding files or directories:

  • --lock
    Require a password to decode the file(s).

  • --recovery
    Generate a recovery key that can be used if the password is lost.

When operating on directories:

  • the password is requested once per command
  • the recovery key (if enabled) is generated once per command
  • the same access credentials apply to all files in the operation

When operating on a single file:

  • the same flags apply, but only affect that file

Planning and dry runs

Glyphlock supports a --plan flag for all commands.

When --plan is used:

  • no files are modified
  • no passwords are requested
  • no recovery keys are generated
  • the operation is printed instead of executed

This allows you to preview exactly what glyphlock would do.

Examples:

glyphlock encode file.txt --plan
glyphlock encode-dir project --plan
glyphlock decode-dir project --plan

Security note

Glyphlock is not encryption.

It is designed to prevent casual or accidental access, not to withstand determined cryptographic attacks.

If you require strong confidentiality against an active adversary, use established encryption tools such as age, gpg, or full-disk encryption.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

glyphlock-0.1.3.tar.gz (9.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

glyphlock-0.1.3-py3-none-any.whl (9.6 kB view details)

Uploaded Python 3

File details

Details for the file glyphlock-0.1.3.tar.gz.

File metadata

  • Download URL: glyphlock-0.1.3.tar.gz
  • Upload date:
  • Size: 9.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.10.12

File hashes

Hashes for glyphlock-0.1.3.tar.gz
Algorithm Hash digest
SHA256 cad296e46737f0e36833db9f8ad7f1ddbbced24f56fb9a87fe1d79d4032c813f
MD5 d627dc6c174cbaedc5419fefc6b72d43
BLAKE2b-256 aec559c156d64b93fac5c8e6b67698e601458c33615f7ae2d3a89e763e3e924e

See more details on using hashes here.

File details

Details for the file glyphlock-0.1.3-py3-none-any.whl.

File metadata

  • Download URL: glyphlock-0.1.3-py3-none-any.whl
  • Upload date:
  • Size: 9.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.10.12

File hashes

Hashes for glyphlock-0.1.3-py3-none-any.whl
Algorithm Hash digest
SHA256 c772dead38a17f8a804b81709f5748356f949cda85d12f18d707a389fac5aea4
MD5 78d4b2453eff6598d2dc6a78846d356b
BLAKE2b-256 a594b36c11bef26d3c3297d35b980210a27e3435bfc63fa2a294ccc2f3422556

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page