[[TOC]]
Introduction
Steganos Software GmbH is a German company that has been offering secure solutions across Europe and internationally for nearly three decades. The company’s name is derived from steganography, the practice of hiding information within other data. Steganos Data Safe is a part of its portfolio worthy of the name.
Over the years, this application has been continuously refined to address the growing demand for stronger encryption and enhanced security mechanisms. While these changes strengthen user data protection, they also present a significant challenge for the digital forensic community.
Passware Kit recovers passwords and decrypts Steganos Data Safe vaults.
Versions and encryption changes
Since its initial release, Steganos Data Safe has improved significantly, introducing new cryptography options and applying stronger encryption algorithms. The overall stages can be summarized as follows:
-
Early versions (Steganos Safe up to v.14): Various key derivation and encryption mechanisms were implemented; the latest version within this group uses .SLE containers with the PBKDF2-SHA1 function for key derivation and AES-256 for encryption.
NoteThese versions are not supported by Passware Kit. - Container-based later versions (Steganos Safe v.15–v.22.4): .SLE containers with PBKDF2-SHA1 key derivation and AES‑XEX encryption with 384‑bit keys.
- File-based recent versions (Steganos Data Safe v.22.5 onward): .SHEADER root file, which uses Argon2 for key derivation and various AES modes for data encryption.
In version 19, Steganos Data Safe introduced two-factor authentication using a Time-based One-Time Password (TOTP). This was followed by implementing an emergency password and a USB-stored key in version 22. With version 22.5, the software switched from .SLE container-based storage to a file-based encryption model, fundamentally changing the structure of the encrypted data.
Passware Kit supports password recovery and data decryption for Steganos Data Safe starting from v.15, enabling investigators and forensic experts to access the encrypted data.
| Steganos Safe / Data Safe version | Format | Protection, Key Derivation Function (KDF) |
Additional options |
GPU-accelerated password recovery |
| v.15-v.22.4 | SLE container | Master password, PBKDF2-SHA1 | • 2FA* • Emergency password |
YES |
| v.22.5 onward | File-based, .SHEADER root file | Master password, Argon2id | • 2FA • Emergency password • USB-stored key |
YES/NO** |
* Passware Kit does not support .SLE containers additionally protected with 2FA and/or Emergency password.
** Argon2id KDF does not support GPU acceleration.
Vault Types and Compatibility
Steganos Data Safe offers various architectural configurations to accommodate different storage and privacy requirements.
- Cloud safe: Enables encrypted data synchronization with cloud services. Fully supported by Passware Kit.
- Safe-in-safe & Partition safe: Legacy features for nested or divided storage. Passware Kit supports such vaults only for v.15-v.22.4.
- Portable safe: Designed for easy mobility across different environments. Not supported by Passware Kit.
- Hidden safe: Uses steganographic techniques to conceal the vault's existence. Not supported by Passware Kit.
Decrypting Steganos Data Safe with Passware Kit
Steganos Data Safe vaults – including legacy .SLE files and new .SHEADER files – are detected using the built-in Find Encrypted Files option. Additionally, USB-stored .SXF files can be detected to allow faster or even instant decryption. For the new file-based encryption, introduced in Steganos Data Safe version 22.5, Passware Kit recognizes the additional security options and can leverage them to increase the speed of recovering a Master password.
Each of the additional security options provides various mechanisms that can be applied to improve the Master password recovery speed and decryption process:
- USB-based Key Device (.SXF) - the SXF file contains a recovery key that allows instant decryption of the Data Safe vault. Typically, such files are stored on USB disks and can be detected by Passware Kit’s “Find Encrypted Files” option.
-
Emergency Password (.EPK) - an additional password set by the user as a backup option. Its encryption is weaker than the Master password’s and enables a faster brute-force process by utilizing GPU. When the “Emergency password” option is selected in Passware Kit, it is added to Batch Mode, enabling recovery attacks for both Emergency and Master passwords. Any password recovered first can decrypt the Steganos Data Safe vault.
-
Two-factor authentication (2FA) - uses a TOTP secret key to further protect the vault. If the TOTP secret key is acquired, it significantly increases the speed of recovering a Master password. For example, recovery speeds can reach 1,865,000 passwords per second on an NVIDIA GeForce RTX 4070 Ti for a Master password with a known TOTP secret key, compared to approximately 1.2 passwords per second on an Intel Core i7 CPU for a regular Master password. The TOTP secret key can be extracted from a QR code generated during Steganos Data Safe setup or found in password managers or TOTP applications. The key uses the Base32 encoding, e.g., “JBSWY3DPEHPK3PXP”, and its format is defined in RFC 6238.
Upon successful password recovery, the decryption of the vault is optional, with the exception of cases using the USB-based Key Device option, which allows immediate decryption of the vault.
Summary
Passware Kit recovers passwords and decrypts Steganos Data Safe vaults in its Business, Forensic, and Ultimate editions.
The table below summarizes the versions and options that Passware Kit supports.
| Options | v.15-v.22.4 (SLE) | v.22.5 onward (SHEADER) |
| Steganos Data Safe additional options | ||
| Two-factor authentication | N/A | YES |
| Emergency password | N/A | YES |
| USB-stored key | N/A | YES |
| Steganos Data Safe types | ||
| Portable safe | NO | NO |
| Cloud safe | YES | YES |
| Safe-in-safe | YES | N/A |
| Partition safe | YES | N/A |
| Hidden safe | NO | NO |
| Passware recovery options | ||
| GPU-accelerated password recovery | YES | YES/NO* |
| Instant decryption | NO | YES** |
* Depending on the additional protection options set.
** Only with an available USB-stored key.
The evolving security architecture of Steganos Data Safe presents a dual challenge: it raises the bar for unauthorized access while simultaneously offering "shortcuts" for decryption if secondary keys are acquired. For the digital forensic community, features like 2FA and Emergency Password represent a trade-off between heightened security and accelerated recovery. Passware Kit is designed to handle this complexity, utilizing high-performance GPU clusters and distributed computing to efficiently process these multi-factor requirements, providing access to the encrypted Steganos vaults.
Comments
0 comments
Article is closed for comments.