Encrypting an investigation file
An investigation file gathers names, addresses and a line of reasoning. Here is what local encryption shields, what it leaves open, and the few habits that make the difference.
An investigation file is rarely harmless. It gathers names, addresses, numbers, sometimes photographs, and above all the reasoning that ties them together. That last part is often the most sensitive: the information already existed, scattered; your work is what brought it together.
Laptops get lost, drives get resold, workstations get shared. Encryption answers those situations, and only those. This guide says which.
What encryption protects
Encryption at rest makes a file unreadable until it is opened. In practice it covers five situations:
- a machine switched off or locked, lost or stolen;
- a drive seized, resold or sent for repair;
- a backup uploaded to an online service;
- a browser profile copied from another account on the machine;
- a colleague opening the developer tools on a shared workstation.
In each of them the attacker holds the file but not the key. Without the password, what they get is indistinguishable from noise.
What it does not protect
This deserves to be said just as plainly. An open session is not protected. The file is decrypted in memory, displayed on screen, and anything running on the machine can reach it: a keylogger, a malicious browser extension, someone standing behind you.
Encryption therefore replaces none of the ordinary habits: lock your session, be wary of extensions, do not work on a machine you cannot vouch for.
It does not protect against forgetting, either. With no account and no server, nobody holds a spare copy of your key. A lost password, without a recovery code, leaves the file permanently unreadable. That is the price of a tool that sends nothing to anyone.
Local does not mean fragile
The common intuition says a hosted tool is better guarded than a local one. For an investigation file, the opposite is often true.
An online service holds your data and holds the key. It can therefore read it, and it can be compelled to hand it over. Its security protects you from its other customers, not from itself.
A local tool holds nothing. The file never leaves your machine, exists on no server, and no order can demand it from a third party who does not have it. The trade-off is real: backups and the password become entirely your responsibility.
The password decides everything
This is where the numbers speak clearest. Serious encryption slows every attempt by a fixed factor. What varies, by an enormous factor, is how hard your password is to guess.
With a modern derivation and decent hardware, count on roughly twenty thousand attempts per second for an attacker with a gaming graphics card.
- A password found in a wordlist, even dressed up with digits, falls in seconds. The list is already written.
- Eight random letters hold for a few months against one machine, a few days against a room full of them.
- Four ordinary words drawn at random, such as
cabin-rust-tempo-fig, hold for thousands of years.
Length beats complexity. A four-word phrase is effortless to remember and resists far better than P@ssw0rd!. Recent public guidance, from NIST and its European counterparts alike, says the same thing: stop demanding capitals and symbols, encourage length.
Write the recovery code down
Local encryption without a safety net is a trap that closes on its owner. The net is a recovery code: a random string that opens the file in place of the password.
It is only useful if kept somewhere other than the machine it protects. On paper, in a safe, in a password manager: the medium matters little, the place does.
The file you hand over
A file encrypted on your machine becomes readable again the moment it leaves. Exporting means producing a copy that no longer carries your protections.
A file meant for a colleague must therefore carry its own password, sent through a channel other than the file itself. A password sent in the same email as the attachment protects nothing.
An image of the map cannot be encrypted. A PNG or SVG export shows the labels in the clear, which is precisely what it is for. Treat it as an ordinary document.
What Ositra does
Cases live on your machine, with no account and no server. Protection turns on when you decide: a password, a recovery code to write down, and every case is encrypted, titles included. A list of case names in the clear would often tell as much as the cases themselves.
The session locks after a quarter of an hour without activity, or on demand. The key lives in memory only: reloading the page loses it.
An exported file receives its own password, separate from the one guarding your vault, since its recipient cannot have yours.
The technical choices, including what they do not protect, are published in the project’s architecture decisions.
Move from reading to mapping.
Ositra brings your entities and their links onto one surface, on your own computer.
Open Ositra