Qu'est-ce que le format de fichier BCUP ?
Un fichier .bcup est un coffre-fort de mots de passe chiffré créé par Buttercup, un gestionnaire de mots de passe gratuit et open-source écrit par le développeur Perry Mitchell. Il stocke les identifiants, les notes sécurisées, les détails de paiement et d'autres informations d'identification dans un fichier unique que seul Buttercup peut lire.
Le contenu est protégé par un chiffrement AES-256 en mode CBC. La clé de chiffrement est dérivée de votre mot de passe maître en utilisant de nombreux cycles de PBKDF2, et un HMAC SHA-256 protège les données contre toute altération. Avant le chiffrement, le coffre est sérialisé en texte et compressé en GZip. Les coffres plus anciens utilisent le « Format A », qui enregistre l'historique complet des modifications du coffre et augmente donc avec le temps ; les coffres plus récents utilisent le « Format B », une structure JSON compacte qui peut réduire la taille du fichier à une fraction de l'ancienne disposition.
Sécurité et sûreté
RISQUE : LOWA .bcup file is inert encrypted data, not executable, so opening it cannot run code. The real risk is confidentiality: it contains your passwords protected only by your master password, so anyone who obtains the file can attempt to brute-force it. Use a strong master password and keep backups, because losing the password makes the vault unrecoverable.
Détails du format
en brefProgrammes qui ouvrent les fichiers BCUP
Détails techniques
spécifications approfondies| Encoding | Text wrapper containing Base64-encoded binary ciphertext |
| Byte order | N/A (text-delimited container) |
| Container | iocane-encrypted payload wrapping GZip-compressed vault data |
| Compression | GZip applied to the serialized vault before encryption |
| Encryption | AES-256 in CBC mode; key derived from the master password via PBKDF2 (many rounds, salted); SHA-256 HMAC computed over the encrypted data for integrity/authentication |
| Typical size | A few kilobytes to a few megabytes depending on entry count and stored attachments |
| Structure | The vault is first serialized (Format A: line-by-line command history; Format B: JSON), GZip-compressed, then AES-256-CBC encrypted. The encrypted output plus its salt, IV, iteration count and HMAC are packed into a delimited text string and written to the .bcup file. |
| Integrity | SHA-256 HMAC verifies both integrity and authenticity before decryption; a wrong master password or tampering causes decryption to fail |
| Encryption Detail | PBKDF2 key derivation, AES-256-CBC cipher, SHA-256 HMAC, per-vault random salt and IV |
| Platforms | Windows, macOS, Linux, Android, iOS |
| Notes | Format A stored the vault's full command history, so files grew on every change even after deletions. Format B switched to a compact JSON structure, cutting file sizes to roughly 20-50% of Format A. Encrypted attachments are stored separately in a .buttercup directory beside the .bcup file. |
| Structure Summary Formats | Format A = deltas/command list; Format B = JSON vault tree with groups and entries |
| Publié | 2015 |
| Dernière version | Format B (JSON-based vault structure) |
| Spécification | github.com |
Conversions BCUP
Q&R de la communauté
posées par les utilisateursPas encore de questions - soyez le premier à poser une question sur les fichiers BCUP.