# I'm archiving Picocrypt

**URL:** https://discuss.privacyguides.net/t/im-archiving-picocrypt/29785
**Category:** General
**Created:** 2025-08-05T16:11:27Z
**Posts:** 29

## Post 1 by @HACKERALERT — 2025-08-05T16:11:27Z

> <https://github.com/Picocrypt/Picocrypt/issues/134>
>
> Hey Gemini, I need your help analyzing and understanding a final parting message… left by a developer for his archived open-source file encryption software. Can you me with that?

It’s not ideal but that’s life. I’m moving into a different direction and am cleaning up some loose ends. I want to make sure I do the best I can for the project and its users before leaving. Read the issue fully… it’ll explain in detail. I think it’s also an interesting and somewhat ironic format.

Looks like this means Picocrypt will no longer qualify to be listed on PG since Picocrypt for macOS will probably break soon and it won’t be cross platform anymore. The PG community can decide how to handle that, whether to keep, delist, redirect to a fork in the future, or something else.

I just want to make it clear that the software is still fully functional and no different, it’s just frozen. Unless the core cryptographic design is problematic, which is unlikely, you can continue using it for as long as you can get it running or running from source.

Open to questions and will stick around for 5 days, then I’ll hop off. Sorry for any inconvenience this may cause. It is my hope that the community will pick it back up again, but I offer no pointers nor have any ideas. The only case I would consider linking to a successor is if PG itself forks Picocrypt into their GH organization because PG is as close to trustable as I would consider (no offense). But of course, not expecting anyone to do anything.

---

## Post 2 by @KevPham — 2025-08-05T16:36:00Z

> [@HACKERALERT](#):
>
> It’s not ideal but that’s life. I’m moving into a different direction and am cleaning up some loose ends. I want to make sure I do the best I can for the project and its users before leaving. Read the issue fully… it’ll explain in detail. I think it’s also an interesting and somewhat ironic format

Thank you so much for sharing this statement with us. While it may not be the best circumstances, everything you mentioned about “vibe coding” demonstrates how it can suck the life out of what it means to create personal projects like yours. I really appreciate your honesty and wish the best for your future endeavors!

---

## Post 3 by @anon11657877 — 2025-08-05T17:58:34Z

So now what are we supposed to use to encrypt our files?

---

## Post 4 by @overdrawn98901 — 2025-08-05T17:59:16Z

Are there any forks you recommend?

---

## Post 5 by @anon57862721 — 2025-08-05T18:13:46Z

Cyrptomator still stands strong.

---

## Post 6 by @KevPham — 2025-08-05T20:04:44Z

For starters, I have no idea if anyone in the PG community is willing maintain a fork of Picocrypt for the long run. It shouldn’t be _too_ difficult though since maintaining Pictocrypt is much easier than creating it from scratch.

> [@anon57862721](#):
>
> Cyrptomator still stands strong.

That and veracrypt :wink:

---

## Post 7 by @anon11657877 — 2025-08-05T20:07:57Z

Isn’t Cryptomator for cloud storage?  
And isn’t Veracrypt proprietary?

---

## Post 8 by @HACKERALERT — 2025-08-05T20:09:14Z

VeraCrypt is open source, arguably the safest option if using Picocrypt is out of the question for you completely. Can’t go wrong with either Cryptomator or VeraCrypt. You can still use Cryptomator locally, it’s just designed in a way to function well with cloud storage.

---

## Post 9 by @anon57862721 — 2025-08-05T20:10:16Z

> [@anon11657877](#):
>
> Isn’t Cryptomator for cloud storage?

You can encrypt any file anywhere. Doesn’t need to be cloud. But it is more famous for using it to encrypt files in big tech cloud. But it is not a necessity.

---

## Post 10 by @anon11657877 — 2025-08-05T20:13:36Z

> [@HACKERALERT](#):
>
> VeraCrypt is open source

Under which license?

> [@HACKERALERT](#):
>
> if using Picocrypt is out of the question for you completely

If nothing else I’ll just keep using it.

> [@anon57862721](#):
>
> You can encrypt any file anywhere. Doesn’t need to be cloud. But it is more famous for using it to encrypt files in big tech cloud. But it is not a necessity.

What about entire folders?

---

## Post 11 by @anon57862721 — 2025-08-05T20:23:31Z

> [@anon11657877](#):
>
> What about entire folders?

Yes, of course. Any file or folder.

Instead of wondering more, why don’t you try it out? Takes like 5 mins at most.

---

## Post 12 by @anon73250778 — 2025-08-05T22:16:50Z

Thank you for the project! I still think it is a cool little app.

---

## Post 13 by @overdrawn98901 — 2025-08-05T22:47:57Z

> [@KevPham](#):
>
> For starters, I have no idea if anyone in the PG community is willing maintain a fork of Picocrypt for the long run. It shouldn’t be _too_ difficult though since maintaining Pictocrypt is much easier than creating it from scratch.

I’ve been studying cryptography lately, and have had some interest in helping out the FOSS world. Maintaining a “complete” project might be a good way to get involved. Seems like the main ongoing support will be for MacOS, which I sadly don’t have at the moment. Don’t want to make any promises, but it sounds interesting to me.

---

## Post 14 by @librefish — 2025-08-06T01:43:59Z

Another option is to just use GNU Privacy Guard (gpg). It can be used from the command line or the gpg4win package comes with a couple of different graphical tools. With it you can encrypt/decrypt/sign files or messages with private keys.

Cryptomator would be easier for some workflows though.

---

## Post 15 by @PaleCrow55 — 2025-08-06T01:56:22Z

[age](https://github.com/FiloSottile/age?tab=readme-ov-file) is meant to be an alternative to PGP as far as file encryption goes, solving some part of [The PGP Problem](https://www.latacora.com/blog/2019/07/16/the-pgp-problem/) .

---

## Post 16 by @TheDoc — 2025-08-06T02:40:39Z

Apologies if I’m wrong (not a dev) but I’m glancing at the [project on GitHub](https://github.com/Picocrypt/Picocrypt?tab=GPL-3.0-1-ov-file) and it seems the license [is unclear](https://www.gnu.org/licenses/identify-licenses-clearly.en.html). Since the torch may be passed onto someone else, I figure it’d be important to clarify if it is under the GPL-3.0-only or GPL-3.0-or-later license.

Thanks for the countless hours you put into developing PicoCrypt!

---

## Post 17 by @HACKERALERT — 2025-08-06T02:54:46Z

I’m not aware of a GPL-3.0-later license since GPLv3 is the newest afaik, but I’m happy to let Picocrypt go under GPL-3.0-or-later (you can quote this if ever in doubt). I didn’t really think much about the license when I started the project and just slapped on GPLv3 to prevent any liability and since it’s standard practice for FOSS. In retrospect, this appears to be the right choice since it requires downstream forks/modifications to also be open source for the public benefit.

---

## Post 18 by @anon63378630 — 2025-08-06T02:56:38Z

@HACKERALERT  
please see the section 14 in the license  
and more importantly the “How to Apply These Terms to Your New Programs” which states it must be set in the header of each applicable file.  
you can alternatively use the SPDX identifier: `GPL-3.0-only` or `GPL-3.0-or-later`

---

## Post 19 by @HACKERALERT — 2025-08-06T03:02:40Z

Thanks for the pointer, I’ll update Picocrypt.go to append “or later”.

If I add a # License section to the README and explicitly state all of the Picocrypt organization’s code is `GPL-3.0-or-later`, would that be good as well?

edit; just realized replied to the wrong person, oops.

---

## Post 20 by @anon63378630 — 2025-08-06T03:04:06Z

> [@HACKERALERT](#):
>
> append  
> would that be good as well

ianal, that would clear it up well  
thank you

---

## Post 21 by @HACKERALERT — 2025-08-06T03:32:12Z

Hmm it seems that the current license appears to by GPLv3 only. It seems I cannot change a project’s license unless all contributors are on board. I think I’ll just state GPLv3 only explicitly then which should make it very clear and non problematic.

---

## Post 22 by @HACKERALERT — 2025-08-06T03:54:49Z

Okay, added:

All original code (non-forked repositories) in the [Picocrypt organization](https://github.com/orgs/Picocrypt/repositories) is licensed under **GPL-3.0-only**. This includes the GUI, CLI, and web application. Forked repositories retain their respective upstream licenses.

Should be pretty clear now (but ianal either).

---

## Post 23 by @any1 — 2025-08-06T12:29:19Z

Thank you for your work on Picocrypt—it was and still is a nice program to use—and I wish you all the best in your future endeavours!

---

## Post 24 by @HACKERALERT — 2025-08-07T02:54:48Z

The GitHub issue has developed a lot since then to say the least… please read the latest few messages. Notably, I’m considering appointing a successor if I can find a trustable one.

---

## Post 25 by @HACKERALERT — 2025-08-07T13:53:26Z

Anyone want to be an Owner/Member of the Picocrypt-NG GitHub org? If so, give me your handle, let me know your commitment (willing to stay for long-term? you don’t have to code, just assist in reviewing PRs, etc.), and any other details. No promises, I will need to vet each person as best as I can but admittedly that is not a perfect process.

Notably, anyone from the core PG team willing to be an Owner? You don’t have to do much other than be a backup in case everyone else goes offline and no one can add new members.

---

## Post 26 by @HACKERALERT — 2025-08-07T17:00:01Z

> **[Picocrypt-NG](https://github.com/Picocrypt-NG)**
>
> The community-led continuation of the @Picocrypt encryption tool. - Picocrypt-NG

---

## Post 27 by @ph00lt0 — 2025-08-07T21:19:52Z

> [@HACKERALERT](#):
>
> Notably, anyone from the core PG team willing to be an Owner? You don’t have to do much other than be a backup in case everyone else goes offline and no one can add new members.

Without having spoken about this with the others my thought on this is that doing that isn’t a good idea. It would damage our independence and create a conflict of interest regardless of any possible good intentions. It would surely complicate listing the fork even if it succeeds.

Generally I wanted to say thanks for doing this great work for quite some time! Despite of that I feel also one again think that we should be more vigilant on projects that are dependent on a single person. It says nothing about your efforts, I’d take my hat off for that.

---

## Post 28 by @HACKERALERT — 2025-08-07T21:21:27Z

That makes sense, thanks for pointing it out. I’ve picked a few people already for the new org and it should be fine now.

---

## Post 29 by @HACKERALERT — 2025-08-08T02:00:05Z

I’ve been receiving some… unideal… comments in other places and emails and it’s really starting to take a toll on me. It seems like I’m the one that needs to touch some grass. So I’m signing off. I’ve set up a successor which I think is the big important takeaway in this thread. Thank you all of PG for being engaging, friendly, and supportive. PG is one of the best online communities I’ve had the pleasure of seeing. Farewell!
