先分清:快照,还是互联同步First, tell them apart: snapshot or encrypted sync
Novara 有两套"把数据带出去"的能力,解决的问题不一样:
Novara has two ways of "taking data out", solving different problems:
| 安全快照(本篇) | 互联同步 | |
|---|---|---|
| 一句话 | 导出一个加密的单文件网页 | 数据在设备之间双向同步 |
| 需要服务器吗 | 不需要(丢到任意静态托管即可) | 需要,你自己搭 |
| 只读还是可编辑 | 永远只读(静态文件) | 手机端可查看、可编辑 |
| 数据新鲜度 | 导出那一刻的快照 | 每次同步都是最新的 |
| 适合谁 | 只想在手机上翻一下、又不愿折腾服务器 | 想让手机成为真正可用的第二个入口 |
| Secure snapshot (this guide) | Encrypted sync | |
|---|---|---|
| In one sentence | Exports one encrypted single-file web page | Data syncs both ways between devices |
| Needs a server? | No (drop it on any static host) | Yes, one you deploy yourself |
| Read-only or editable? | Always read-only (a static file) | The phone can view and edit |
| Freshness | The vault as of the export moment | Up to date on every sync |
| Best for | A quick look on the phone without running a server | Making the phone a genuinely usable second entrance |
只要"看一眼" → 用安全快照就够了,它简单得多。要"改一条备忘、勾一个待办" → 需要互联同步。本篇只讲快照。
If you only need to look something up → a secure snapshot is far simpler. To edit a memo or tick a to-do → you want encrypted sync. This guide covers snapshots only.
安全快照Secure snapshots
导出的是什么
What gets exported
快照是导出那一刻整库的加密只读副本,形态是一个自包含 HTML 文件(默认名 index.html):查看器(样式与逻辑全部内联)+ 密文块。密文块就是标准 .novaenc v4 容器的原始字节。
A snapshot is an encrypted, read-only copy of the whole vault as of the export moment, shaped as one self-contained HTML file (default name index.html): the viewer (all styling and logic inlined) + the ciphertext block. That block is the raw bytes of a standard .novaenc v4 container.
- 文件内只有两块非敏感明文:导出时间戳与程序版本——页面上"数据截至 …"就是它。
- 浏览器内四分区只读浏览、全局搜索、TOTP 动态码、字段掩码与复制按钮——手机看动态码正是它的高频场景。
- 没有编辑、没有上传、没有任何持久化:密码与解密结果只活在当前页面内存,刷新就要重新输口令。
- 移动优先的界面,深浅双主题跟随系统。
- Only two pieces of non-sensitive plaintext live in the file: the export timestamp and the app version — the "data as of …" line on the page.
- In the browser: read-only browsing of all four areas, global search, TOTP codes, field masking and copy buttons — checking a one-time code on your phone is its most frequent job.
- No editing, no uploading, no persistence of any kind: the passphrase and decryption live only in the current page's memory; refreshing asks for the passphrase again.
- A mobile-first interface with light and dark themes that follow the system.
默认名 index.html 是刻意的:它是所有 Web 服务器的默认文档名,扔进目录即 https://域名/路径/ 零配置可访问;重新导出同名覆盖,URL 恒定不变。本机双击(file://)在现代浏览器下加解密能力可用;个别浏览器能力不足时按提示改走静态托管。
The default name index.html is deliberate: it is every web server's default document, so dropping it into a directory makes it reachable at https://domain/path/ with zero configuration; re-exporting overwrites the same name and the URL never changes. Opening it locally (file://) works with modern browsers' crypto; on the rare browser without sufficient capability, follow the prompt and use static hosting instead.
为什么导出物永远是密文
Why the export is always ciphertext
导出必须设口令(复用隐私锁密码,或独立口令两次确认),不存在空口令路径——不存在产出明文快照的操作序列。容器内:
Exporting requires a passphrase (reuse the privacy-lock password, or an independent one confirmed twice) — there is no empty-passphrase path, and no sequence of actions can produce a plaintext snapshot. Inside the container:
- AES-256-GCM 认证加密,密钥由口令经 PBKDF2-SHA256(300 万次迭代)派生;
- 每个文件独立随机盐;44 字节自描述头部整体作为认证范围——篡改任何头字段解密必败;
- 数据先 GZip 再加密,密文块的明文形态从头到尾没有落过盘。
- AES-256-GCM authenticated encryption, the key derived from the passphrase via PBKDF2-SHA256 (3 million iterations);
- a fresh random salt per file; all 44 bytes of the self-describing header are inside the authenticated range — tampering with any header field makes decryption fail;
- data is GZipped before encryption, so the plaintext form of the ciphertext block never touches disk at any point.
托管方(NAS、对象存储、网盘)看到的只是这个文件本身。它仍可能记录访问、保留副本——但这些副本没有口令就解不开。
A host (NAS, object storage, cloud drive) sees only this file. It may still log access or keep copies — but those copies cannot be opened without the passphrase.
分享的正确姿势
How to share it properly
- 文件与口令分两个渠道发:文件走一个,口令走另一个(电话、另一款 IM)。同渠道同发等于没加密。
- 公网托管建议给文件起随机文件名,防止被扫到。
- 快照是静态的:数据更新 = 重新导出覆盖,旧链接的 URL 恒定不变。
- 想持续看最新数据 → 那是互联同步的活,快照只负责"某个时间点"。
- Send the file and the passphrase through two different channels: file one way, passphrase another (a phone call, a different chat app). Sending both through the same channel cancels the encryption.
- For public hosting, give the file a random file name so scanners do not find it.
- A snapshot is static: data updated = re-export and overwrite; the old link's URL never changes.
- Want continuously fresh data → that is encrypted sync's job; a snapshot only represents "a point in time".
常见问题FAQ
快照在浏览器里打不开,提示加密能力?
说明页面不是安全上下文:file:// 下换现代浏览器(Chrome / Edge / Firefox),或把文件放到 HTTPS 静态托管打开。
快照和加密备份(.novaenc)是什么关系?
同一容器格式、同一头部布局,差别只在"密钥来源"与外壳:备份导入 Novara 还原,快照在浏览器里只读打开。
公开托管快照有风险吗?
托管方仍可能记录访问或保留副本——但副本没有口令解不开。文件名随机化 + 口令分渠道,是标准做法。
The snapshot will not open and mentions encryption capability?
The page is not a secure context: under file:// switch to a modern browser (Chrome / Edge / Firefox), or put the file on HTTPS static hosting.
How does a snapshot relate to an encrypted backup (.novaenc)?
Same container format, same header layout; the difference is the key source and the shell: a backup imports into Novara to restore, a snapshot opens read-only in the browser.
Any risk hosting a snapshot publicly?
The host may still log access or keep copies — but those copies cannot be opened without the passphrase. A randomized file name plus split channels is the standard practice.
继续阅读Keep reading
- Need "the latest data" rather than a point in time → the encrypted sync guide
- Daily use and backups → the daily usage guide