Che cos'è il formato di file BCUP?
Un file .bcup è un archivio di password crittografato creato da Buttercup, un gestore di password gratuito e open-source scritto dallo sviluppatore Perry Mitchell. Memorizza login, note sicure, dettagli di pagamento e altre credenziali in un singolo file che solo Buttercup può leggere.
I contenuti sono protetti con crittografia AES-256 in modalità CBC. La chiave di crittografia è derivata dalla tua master password utilizzando molti cicli di PBKDF2, e un HMAC SHA-256 protegge i dati contro la manomissione. Prima della crittografia, il vault viene serializzato in testo e compresso con GZip. I vault più vecchi utilizzano il «Format A», che registra l'intera cronologia delle modifiche del vault e quindi cresce nel tempo; i vault più recenti utilizzano il «Format B», una struttura JSON compatta che può ridurre la dimensione del file a una frazione del vecchio layout.
Sicurezza e incolumità
RISCHIO: LOWA .bcup file is inert encrypted data, not executable, so opening it cannot run code. The real risk is confidentiality: it contains your passwords protected only by your master password, so anyone who obtains the file can attempt to brute-force it. Use a strong master password and keep backups, because losing the password makes the vault unrecoverable.
Dettagli del formato
in sintesiProgrammi che aprono file BCUP
Dettagli tecnici
specifiche approfondite| Encoding | Text wrapper containing Base64-encoded binary ciphertext |
| Byte order | N/A (text-delimited container) |
| Container | iocane-encrypted payload wrapping GZip-compressed vault data |
| Compression | GZip applied to the serialized vault before encryption |
| Encryption | AES-256 in CBC mode; key derived from the master password via PBKDF2 (many rounds, salted); SHA-256 HMAC computed over the encrypted data for integrity/authentication |
| Typical size | A few kilobytes to a few megabytes depending on entry count and stored attachments |
| Structure | The vault is first serialized (Format A: line-by-line command history; Format B: JSON), GZip-compressed, then AES-256-CBC encrypted. The encrypted output plus its salt, IV, iteration count and HMAC are packed into a delimited text string and written to the .bcup file. |
| Integrity | SHA-256 HMAC verifies both integrity and authenticity before decryption; a wrong master password or tampering causes decryption to fail |
| Encryption Detail | PBKDF2 key derivation, AES-256-CBC cipher, SHA-256 HMAC, per-vault random salt and IV |
| Platforms | Windows, macOS, Linux, Android, iOS |
| Notes | Format A stored the vault's full command history, so files grew on every change even after deletions. Format B switched to a compact JSON structure, cutting file sizes to roughly 20-50% of Format A. Encrypted attachments are stored separately in a .buttercup directory beside the .bcup file. |
| Structure Summary Formats | Format A = deltas/command list; Format B = JSON vault tree with groups and entries |
| Rilasciato | 2015 |
| Ultima versione | Format B (JSON-based vault structure) |
| Specifica | github.com |
Conversioni BCUP
Domande e risposte della community
chiesto dagli utentiAncora nessuna domanda - sii il primo a chiedere informazioni sui file BCUP.