Vad är filformatet BCUP?
En .bcup-fil är ett krypterat lösenordsvalv skapat av Buttercup, en gratis lösenordshanterare med öppen källkod skriven av utvecklaren Perry Mitchell. Den lagrar inloggningar, säkra anteckningar, betalningsuppgifter och andra inloggningsuppgifter i en enda fil som endast Buttercup kan läsa.
Innehållet skyddas med AES-256-kryptering i CBC-läge. Krypteringsnyckeln härleds från ditt huvudlösenord med hjälp av många omgångar av PBKDF2, och en SHA-256 HMAC skyddar datan mot manipulation. Innan kryptering serialiseras valvet till text och GZip-komprimeras. Äldre valv använder «Format A», som registrerar valvets fullständiga ändringshistorik och därför växer över tid; nyare valv använder «Format B», en kompakt JSON-struktur som kan minska filstorleken till en bråkdel av den gamla layouten.
Säkerhet & trygghet
RISK: LOWA .bcup file is inert encrypted data, not executable, so opening it cannot run code. The real risk is confidentiality: it contains your passwords protected only by your master password, so anyone who obtains the file can attempt to brute-force it. Use a strong master password and keep backups, because losing the password makes the vault unrecoverable.
Formatdetaljer
i ett nötskalProgram som öppnar BCUP-filer
Tekniska detaljer
djup specifikation| Encoding | Text wrapper containing Base64-encoded binary ciphertext |
| Byte order | N/A (text-delimited container) |
| Container | iocane-encrypted payload wrapping GZip-compressed vault data |
| Compression | GZip applied to the serialized vault before encryption |
| Encryption | AES-256 in CBC mode; key derived from the master password via PBKDF2 (many rounds, salted); SHA-256 HMAC computed over the encrypted data for integrity/authentication |
| Typical size | A few kilobytes to a few megabytes depending on entry count and stored attachments |
| Structure | The vault is first serialized (Format A: line-by-line command history; Format B: JSON), GZip-compressed, then AES-256-CBC encrypted. The encrypted output plus its salt, IV, iteration count and HMAC are packed into a delimited text string and written to the .bcup file. |
| Integrity | SHA-256 HMAC verifies both integrity and authenticity before decryption; a wrong master password or tampering causes decryption to fail |
| Encryption Detail | PBKDF2 key derivation, AES-256-CBC cipher, SHA-256 HMAC, per-vault random salt and IV |
| Platforms | Windows, macOS, Linux, Android, iOS |
| Notes | Format A stored the vault's full command history, so files grew on every change even after deletions. Format B switched to a compact JSON structure, cutting file sizes to roughly 20-50% of Format A. Encrypted attachments are stored separately in a .buttercup directory beside the .bcup file. |
| Structure Summary Formats | Format A = deltas/command list; Format B = JSON vault tree with groups and entries |
| Släppt | 2015 |
| Senaste version | Format B (JSON-based vault structure) |
| Specifikation | github.com |
BCUP-konverteringar
Frågor & svar
frågat av användareInga frågor än - bli den första att fråga om BCUP-filer.