VaultSort 5.0.1-beta.36
EncryptionSecurity KeysKey SyncUndoOrganize
Adds a way to bring files encrypted by older versions up to the current format, a panel showing which keys can open a file and letting you authorise another, control over which keys a new file is encrypted for, and fixes Undo and Operation History being empty on Windows.
What's New
- See which keys can open an encrypted file. Select a single encrypted file in Secure and a key icon appears beside it. It lists every key authorised for that file by name, marks the format the file uses, and says plainly when only one key can open it — which is the situation a backup key exists to prevent and which nothing in the app previously showed. It also explains why an older file lists so many keys: earlier formats authorised every key registered at the time.
- Authorise another key for a file you have already encrypted. From that same panel, pick a key and add it. It takes one touch on a key that already opens the file and one on the key you are adding, and the panel says so before you start. This replaces the small "+" that used to sit on the Decrypt button, which chose the key for you and put an encryption action on the wrong verb.
- Bring older encrypted files up to the current format. Key Sync now finds files encrypted by older versions of VaultSort and offers to upgrade them. The current format wraps each key in its own slot using your security key's hardware, which is stronger than the older formats and is what makes per-file key management possible at all. A file that only an archived or an older-style key can open can now be upgraded too. (Upgrading re-authorises the file for the keys you choose. Keys that cannot be used with the current format stop opening that file, and VaultSort names them before you commit to anything.)
- Choose which keys a new file is encrypted for. Encrypting used to authorise a single key chosen for you. You can now tick the keys you want, including deselecting the default one, and see the number of touches it will cost before you start.
- A way out when you cannot use the key VaultSort picked. The prompt during a decrypt now offers "use a different key", so a file that also opens with your Touch ID or a second security key is no longer stuck behind a key you do not have to hand.
- Key Sync works on current-format files. It can add a newly registered key to files encrypted before you registered it, rather than only handling old formats.
- Operation History reads consistently. Entries were written in three different formats, one of which depended on the language settings of the machine that wrote it, and the list was not really sorted by time at all. Times are now stored one way and displayed in your own format, newest first.
Bug Fixes
- Fixed Undo and Operation History being empty on Windows. VaultSort and the engine that performs an organize disagreed about where the history lives, so the app read an empty folder while the engine wrote elsewhere. History from before this fix is found and remains undoable.
- Fixed Undo staying greyed out for a folder reached through a symbolic link, on both platforms — a relocated Downloads folder being the common case.
- Fixed a relocated folder appearing as a file in the Directory Browser, where it could not be picked as an organize target.
- Fixed decrypting several items at once using the first item's key for all of them, so a second folder protected by a different key failed while decrypting it on its own worked.
- Fixed a decrypt asking for an archived key while an active key that opens the same file sat unused — which could not be satisfied at all when the archived key was a passkey rather than a hardware key.
- Fixed Key Sync listing files that were already up to date and offering a sync that could not run.
- Fixed Key Sync counting keys it could never add, so it reported keys missing while the chooser beside it offered fewer, or none. Keys that cannot be added are now named, with what to do about them, instead of being folded into a number.
- Fixed Key Sync failing partway with an error naming a key that works perfectly well, by no longer scheduling a touch for a key that cannot provide one.
- Fixed upgrading a folder failing partway through with a permissions error.
- Fixed upgrading a folder that had been renamed since it was encrypted failing to find its own contents. (Nothing was damaged in either case — the encrypted original is never modified until the new one is verified.)
- Fixed a warning that stated the opposite of what an upgrade does to archived keys.
- Fixed one file failing in a multi-file key operation discarding the results for every file already done, on the operation whose whole purpose is knowing which files got the key.
- Fixed several messages that reassured you about things that were not true, including one claiming nothing is decrypted during an operation that decrypts, and one claiming all of your keys were already authorised when they were not.
- Fixed the key chooser hiding itself when you had exactly one usable key, so there was no way to see what would be used.
- Fixed folder paths rendering with the leading slash at the wrong end, and being cut with no sign they had been cut.
