SSQZ/atlasDocs
Backup (preview)

Security model Preview

What SQZ Backup's encryption protects, what it deliberately does not, and how the keys work. Plain .sqz archives are not encrypted; everything here is about sqz backup.

What is protected#

Who it defends against#

WhoWhat they can doWhat stops them
Whoever holds the storage: a cloud provider, a NAS admin, anyone who copies the folderRead every object and see sizes and write times; delete, change, reorder, replace or replay objectsEverything is encrypted and authenticated; object IDs are keyed, so known files cannot be looked up by hash; tampering is detected
A thief of the backup diskThe same, offline, with time to guess passwordsThe same, and the password is stretched with Argon2id (64 MiB of memory per guess)
Accidents: crashes, power loss, full disks, bit rotLeave partial or damaged filesWrite-then-publish order; every object is checked by hash and authentication tag

What it does not protect against#

Cryptography#

No custom ciphers or constructions; only well-reviewed libraries, used as documented.

PurposeChoice
Encryption of every objectXChaCha20-Poly1305 (RustCrypto chacha20poly1305, reviewed by NCC Group in 2020), random 192-bit nonces
Password stretchingArgon2id, 64 MiB, 3 passes (RFC 9106)
Subkeys from the master keyBLAKE3 key derivation, one subkey per purpose
Object IDsKeyed BLAKE3, so IDs of known content cannot be computed
RandomnessThe operating system's generator
Keys in memoryWiped when no longer needed

Keys, passwords and the recovery key#

At init, SQZ makes a random 256-bit master key. It is never stored in the clear, only wrapped in key slots:

A wrong password or recovery key fails cleanly with "wrong password (or this is not the key for this repository)". Adding a password (add-password) wraps the same master key in a new slot; nothing else is rewritten.

Losing every password and the recovery key loses the data

There is no back door. Keep the recovery key written down somewhere safe and separate from the computer you back up.

A swapped config#

Someone with write access could replace the repository's config with one that wraps a key they know, hoping your next backup is written under it. The config is authenticated with a subkey of the master key, and each computer remembers a check value for every repository it has used. A config under another key is refused on those computers.

Not built yet#