Security note: a security audit of EncFS found weaknesses (for example, it does not authenticate/verify metadata integrity against an attacker with repeated access to the encrypted files). The project is unmaintained. For new use prefer
gocryptfs,cryfs, or full-volume LUKS. The notes below are kept for existing EncFS volumes.
Create and mount¶
mkdir -p ~/encfs/{crypt,.crypt}
chmod 0700 ~/encfs
chmod 0750 ~/encfs/{crypt,.crypt}
encfs ~/encfs/.crypt ~/encfs/crypt # first run offers to create it; choose expert/paranoia settings
.crypt holds the encrypted files. crypt is where the decrypted view appears while mounted.
Unmount (locks the data) and mount again¶
fusermount -u ~/encfs/crypt
encfs ~/encfs/.crypt ~/encfs/crypt
Change the volume password¶
encfsctl passwd ~/encfs/.crypt
Troubleshooting: "Permission denied"¶
Usually the volume is already mounted (possibly by another shell). Unmount and retry: fusermount -u ~/encfs/crypt.