Skip to main content

Glyph-based file obfuscation with intentional access control

Project description

Glyphlock

This module contains a simple implementation of glyph-based file obfuscation with optional access control.


What glyphlock does

Glyphlock converts a file into a deterministic representation made up of Unicode Egyptian hieroglyphs.

The original file:

  • is removed
  • is replaced with a .glyph file
  • is no longer readable as plain text

The transformation is fully reversible and does not modify the original data.


What glyphlock is for

Glyphlock is meant to prevent accidental or casual access to files.

It is designed to be used when:

  • files should not be readable at a glance
  • sensitive data should not be opened unintentionally
  • projects need to be parked safely on disk
  • access should require intent

This tool is not encryption and is not designed to protect against determined offline attacks.


Access control

Glyphlock supports optional access gating.

When enabled:

  • a password is required to decode files
  • passwords are verified using a key derivation function
  • passwords are never stored directly

An optional recovery key can also be generated.

The recovery key:

  • is shown once
  • is stored as a hash
  • can be used if the password is lost

If both the password and recovery key are lost, the file cannot be recovered.

Currently Glyphlock allows for a user to create an empty password. If the user does so they must press 'Enter' when prompted for the password.


File behavior

When encoding:

  • the original file is replaced with filename.glyph
  • the original file extension is stored in the header
  • file permissions are preserved
  • the file payload is checksummed

When decoding:

  • the original file is restored exactly
  • permissions are restored
  • corrupted or modified files fail to decode

All file operations use atomic replacement to minimize the risk of data loss.


Directory handling

When operating on directories, glyphlock walks the directory tree recursively.

The following are skipped automatically:

  • symbolic links
  • hidden directories
  • version control metadata (.git, .hg, .svn)
  • virtual environments (.venv, env)
  • Python cache directories (__pycache__)
  • editor configuration directories

Only user-authored files are processed by default.


How to use this module

Glyphlock is used as a command-line tool. Only the encode and encode-directory commands accept access flags. All commands accept --plan flags.

Encode a single file:

glyphlock encode file.txt

Decode a file (decode commands do not accept access flags):

glyphlock decode file.glyph

Encode a directory with a password and recovery key:

glyphlock encode-dir project --lock --recovery

Decode a directory (decode commands do not accept access flags):

glyphlock decode-dir project

Access flags

The following flags are supported when encoding files or directories:

  • --lock
    Require a password to decode the file(s).

  • --recovery
    Generate a recovery key that can be used if the password is lost.

When operating on directories:

  • the password is requested once per command
  • the recovery key (if enabled) is generated once per command
  • the same access credentials apply to all files in the operation

When operating on a single file:

  • the same flags apply, but only affect that file

Planning and dry runs

Glyphlock supports a --plan flag for all commands.

When --plan is used:

  • no files are modified
  • no passwords are requested
  • no recovery keys are generated
  • the operation is printed instead of executed

This allows you to preview exactly what glyphlock would do.

Examples:

glyphlock encode file.txt --plan
glyphlock encode-dir project --plan
glyphlock decode-dir project --plan

Security note

Glyphlock is not encryption.

It is designed to prevent casual or accidental access, not to withstand determined cryptographic attacks.

If you require strong confidentiality against an active adversary, use established encryption tools such as age, gpg, or full-disk encryption.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

glyphlock-0.1.4.tar.gz (9.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

glyphlock-0.1.4-py3-none-any.whl (10.5 kB view details)

Uploaded Python 3

File details

Details for the file glyphlock-0.1.4.tar.gz.

File metadata

  • Download URL: glyphlock-0.1.4.tar.gz
  • Upload date:
  • Size: 9.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.10.12

File hashes

Hashes for glyphlock-0.1.4.tar.gz
Algorithm Hash digest
SHA256 f1b9a8e6e42d71dbca0bfdca8a7ec8edc6cee346f1e378ee697b540ed4f877a6
MD5 b756d148a212eb63d830fe0c37cc8dd4
BLAKE2b-256 b4b27fb01bde435449156989a1f1b8b0b1947f8e32494dba12d46ddaed2e5080

See more details on using hashes here.

File details

Details for the file glyphlock-0.1.4-py3-none-any.whl.

File metadata

  • Download URL: glyphlock-0.1.4-py3-none-any.whl
  • Upload date:
  • Size: 10.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.10.12

File hashes

Hashes for glyphlock-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 e1ec635dd63ab7f1a77e33f965bb0e2bdf287493afe6fda4bcd0f7f9c8223656
MD5 c230b990cde9a7f6e4bb040c7dbd7d63
BLAKE2b-256 ace90129d8f63daac1be1f98505b6ee630a23ab9c8d65d6564d4903d5996dbc8

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page