Hva er BCUP-filformatet?
En .bcup-fil er et kryptert passordhvelv opprettet av Buttercup, en gratis passordbehandler med åpen kildekode skrevet av utvikleren Perry Mitchell. Den lagrer pålogginger, sikre notater, betalingsopplysninger og andre legitimasjonsdata i en enkelt fil som bare Buttercup kan lese.
Innholdet er beskyttet med AES-256-kryptering i CBC-modus. Krypteringsnøkkelen er utledet fra ditt hovedpassord ved bruk av mange runder med PBKDF2, og en SHA-256 HMAC beskytter dataene mot manipulering. Før kryptering blir hvelvet serialisert til tekst og GZip-komprimert. Eldre hvelv bruker «Format A», som registrerer hvelvets fulle endringshistorikk og derfor vokser over tid; nyere hvelv bruker «Format B», en kompakt JSON-struktur som kan redusere filstørrelsen til en brøkdel av det gamle oppsettet.
Sikkerhet og trygghet
RISIKO: LOWA .bcup file is inert encrypted data, not executable, so opening it cannot run code. The real risk is confidentiality: it contains your passwords protected only by your master password, so anyone who obtains the file can attempt to brute-force it. Use a strong master password and keep backups, because losing the password makes the vault unrecoverable.
Formatdetaljer
i et nøtteskallProgrammer som åpner BCUP-filer
Tekniske detaljer
dyp spesifikasjon| Encoding | Text wrapper containing Base64-encoded binary ciphertext |
| Byte order | N/A (text-delimited container) |
| Container | iocane-encrypted payload wrapping GZip-compressed vault data |
| Compression | GZip applied to the serialized vault before encryption |
| Encryption | AES-256 in CBC mode; key derived from the master password via PBKDF2 (many rounds, salted); SHA-256 HMAC computed over the encrypted data for integrity/authentication |
| Typical size | A few kilobytes to a few megabytes depending on entry count and stored attachments |
| Structure | The vault is first serialized (Format A: line-by-line command history; Format B: JSON), GZip-compressed, then AES-256-CBC encrypted. The encrypted output plus its salt, IV, iteration count and HMAC are packed into a delimited text string and written to the .bcup file. |
| Integrity | SHA-256 HMAC verifies both integrity and authenticity before decryption; a wrong master password or tampering causes decryption to fail |
| Encryption Detail | PBKDF2 key derivation, AES-256-CBC cipher, SHA-256 HMAC, per-vault random salt and IV |
| Platforms | Windows, macOS, Linux, Android, iOS |
| Notes | Format A stored the vault's full command history, so files grew on every change even after deletions. Format B switched to a compact JSON structure, cutting file sizes to roughly 20-50% of Format A. Encrypted attachments are stored separately in a .buttercup directory beside the .bcup file. |
| Structure Summary Formats | Format A = deltas/command list; Format B = JSON vault tree with groups and entries |
| Utgitt | 2015 |
| Siste versjon | Format B (JSON-based vault structure) |
| Spesifikasjon | github.com |
BCUP-konverteringer
Spørsmål og svar fra fellesskapet
spurt av brukereIngen spørsmål ennå - vær den første til å spørre om BCUP-filer.