# Encryption tool help needed

**URL:** https://discuss.privacyguides.net/t/encryption-tool-help-needed/38779
**Category:** Questions
**Tags:** please-eli5
**Created:** 2026-06-24T21:55:29Z
**Posts:** 22

## Post 1 by @dixon — 2026-06-24T21:55:29Z

Hi

I use [Picocrypt-NG](https://github.com/Picocrypt-NG/Picocrypt-NG) but I discovered that it is [vibecoded](https://github.com/Picocrypt-NG/Picocrypt-NG#ai-usage), which is huge no-go for me, especially in so sensitive task as encryption.

Can you please advice me good GUI (because I am a beginner) utils for Linux to encrypt files? And better without _sudo,_ because I don’t feel comfortable allowing any app to have root rights on my distribution permanently.

---

## Post 2 by @FranklyFlawless — 2026-06-24T22:51:37Z

You can use LUKS.

---

## Post 3 by @anon32735431 — 2026-06-24T23:28:22Z

For individual files you could use Veracrypt containers or 7-zip. Both have a GUI.

Fedora KDE has GUI vaults built in too. They are LVM and use encryption on the fly too, the vault grows in size as you add files and you don’t need to pre-set it, so that’s cool too. You could probably install this on other distros.

---

## Post 4 by @dixon — 2026-06-24T23:48:56Z

> [@FranklyFlawless](#):
>
> LUKS

On disk, I do. But I need to create encrypted files backup that can be uploaded as single file

> [@anon32735431](#):
>
> Fedora KDE

I am on lubuntu :frowning:

> [@anon32735431](#):
>
> 7-zip

I took a look, seems too “light” for encryption of my attorney documents

---

## Post 5 by @PaleCrow55 — 2026-06-24T23:51:05Z

> [@dixon](#):
>
> seems too “light” for encryption of my attorney documents

“light”?

7zip supports AES256, which is pretty much the standard for symmetric encryption.

---

## Post 6 by @anon32735431 — 2026-06-24T23:54:48Z

If you want to regualrly access and add files, Veracrypt would be better cos you dont need to de/recompress every time. Just open the container and do what you like. If you want to create an archive 7-zip is probably easier. They both support AES-256 so the encryption method itself is not a consideration for either tool.

> [@dixon](#):
>
> encryption of my attorney documents

---

## Post 7 by @dixon — 2026-06-24T23:56:04Z

> [@PaleCrow55](#):
>
> “light”?

Key derivation algorithm is not “safe”. It is not Argon2ID according to my knowledge. Plus this is archiver, not an encryption tool. There is even warning for that…

---

## Post 8 by @dixon — 2026-06-24T23:57:32Z

> [@anon32735431](#):
>
> Veracrypt

On Lubuntu? How? I thought it is microslop only…

Because `apt install veracrypt` do not work

---

## Post 9 by @anon32735431 — 2026-06-24T23:59:18Z

Veracrypt has an AppImage, you can use that.

Also I wouldn’t worry about Argon2 KDF so much, you could create a 64 character password for an AES .7z and absolutely no one will be breaking into that. Though if you really want Argon2, Veracrypt just added it. Just make sure you enable it as it’s not the default KDF.

---

## Post 10 by @PaleCrow55 — 2026-06-25T00:00:49Z

`age` is another option. The standard implementation is a CLI, but there are some (in-browser) GUIs available.

---

## Post 11 by @dixon — 2026-06-25T00:02:25Z

> [@anon32735431](#):
>
> Veracrypt has an AppImage

Is it safe to do so? Because everyone tells me not to download anything executable and use apt only.

Sorry for dumb questions, I just try to become more familiar with all this…

---

## Post 12 by @FranklyFlawless — 2026-06-25T00:05:28Z

> [@dixon](#):
>
> Is it safe to do so?

That depends on your threat model.

---

## Post 13 by @anon32735431 — 2026-06-25T00:07:21Z

Yes it’s safe.

You can can verify the AppImage using the gpg. There are instruction on the website how to do that.

If it’s just for local storage and not to send to anyone you could also just LUKS encrypt a USB and store it all there. Then the whole drive is encrypted with AES-256 with Argon2 KDF. In this case you could only access on Linux systems though.

---

## Post 14 by @JohnDose — 2026-06-25T01:19:54Z

Won’t recommend 7zip since it’s not intended for serious encryption. There are some discussions that 7zip’s implementation are not rigorous enough(such as key iteration rounds).

PeaZip is better in terms of security. However, age is best recommended for individial file encryption

---

## Post 15 by @KathyM — 2026-06-25T02:21:43Z

The original picocrypt project wasn’t vibe coded. [GitHub - Picocrypt/Picocrypt: A very small, very simple, yet very secure encryption tool. · GitHub](https://github.com/Picocrypt/Picocrypt)

It’s publicly archived but it’s still a solid app. Developer froze features and ironed all bugs he could find before locking it.

---

## Post 16 by @anon32735431 — 2026-06-25T03:28:02Z

> [@JohnDose](#):
>
> There are some discussions that 7zip’s implementation are not rigorous enough

Do you have a source? I’d be interested to read more about this.

---

## Post 17 by @JohnDose — 2026-06-25T08:50:10Z

> <https://crypto.stackexchange.com/questions/90137/7-zip-encryption-practical-effect-of-lacking-salt>

the issue is fixed, but it’s clear that 7zip shouldn’t be the main tool for encryption(it’s just not made for that purpose). Other unfound trivial/nontrivial suboptimal practices may still exist. age, picocrypt are much better options. I personally use peazip as my file explorer

---

## Post 18 by @random_penguin — 2026-06-25T20:01:19Z

Why not use simply `openssl enc`? Sure, it’s a console app, but it’s been around for ages and will likely remain to be even after VeraCrypt and similar apps become defunct. Easily accessible, feature rich, accessible docs. This is all important if you’re backing up for the long term. Typing `openssl enc --help` in a terminal will get you a long way.

---

## Post 19 by @Ozzy — 2026-07-19T09:02:35Z

Would AxCrypt be an option? [https://axcrypt.net/](https://axcrypt.net/)

I liked earlier versions more then the latest. But it check some of the boxes that original poster seeks.

---

## Post 20 by @PaleCrow55 — 2026-07-19T13:47:55Z

> **[AxCrypt Pricing – File Encryption Plans for All Users](https://axcrypt.net/pricing/)**
>
> Compare AxCrypt’s Free, Premium, and Business plans. Get AES-256 encryption, password manager, and secure file sharing. Start your 14-days free trial today!

\> Requires payment to encrypt more than 2 files per month.

> [@Ozzy](#):
>
> Would AxCrypt be an option?

I would say no.

---

## Post 21 by @TheDoc — 2026-07-19T15:01:29Z

> [@dixon](#):
>
> I use [Picocrypt-NG](https://github.com/Picocrypt-NG/Picocrypt-NG) but I discovered that it is [vibecoded](https://github.com/Picocrypt-NG/Picocrypt-NG#ai-usage), which is huge no-go for me, especially in so sensitive task as encryption.

Picocrypt-NG doesn’t [vibe code](http://vibe-coded.urbanup.com/18530338) (code purely based on vibes barfed out by an AI) crypto-critical code in the project, it is however AI-assisted (reviewed and modified by humans) as explained in [their documentation](https://github.com/Picocrypt-NG/Picocrypt-NG#ai-usage):

> The cryptographic core derives from the audited Picocrypt (Radically Open Security, 2024 — no major findings) and stays regression-pinned to the archived audited build and frozen golden vectors, so AI-assisted changes cannot silently alter the audited behavior or the volume format. All crypto-critical code receives human review before merging.

That last sentence makes me wonder if they vibe code non-critical parts of their software? More clarification from them would be great. While there are many arguments to be made regarding the negative impacts of AI, an increase in security vulnerabilities from AI-assisted code doesn’t seem to be one of them. If you have a strong stance on boycotting even AI-assisted code, you better switch away from Linux as well: [Linus Torvalds to critics of AI coding in Linux: "Fork it. Or just walk away." - Ars Technica](https://arstechnica.com/ai/2026/07/linus-torvalds-to-critics-of-ai-coding-in-linux-fork-it-or-just-walk-away/)

---

## Post 22 by @eyJhbG — 2026-07-20T17:35:28Z

> [@dixon](#):
>
> I use [Picocrypt-NG](https://github.com/Picocrypt-NG/Picocrypt-NG) but I discovered that it is [vibecoded](https://github.com/Picocrypt-NG/Picocrypt-NG#ai-usage), which is huge no-go for me, especially in so sensitive task as encryption.

“Vibe coding” defined as a non-technical person building any security-based application in a beginner platform like Lovable or Base44 and releasing it publicly for consumption is absolutely a concern. Further to @TheDoc ‘s post above AI-assisted coding has become the status quo for most modern, software development. Almost every developer in my circle is using LLMS to write, maintain and test code because the technology has become so overwhelmingly good that it would be crazy not to. I’d be less concerned with a developer of a secure application using AI-assisted coding as it’s become more accurate and efficient than most humans are capable of achieving in their own, when done correctly and subject to human review. What is their track record of integrity, do they have any history of vulnerabilities, how often are they audited and the like are probably more important points in general.
