Home / Alt manpages / pbputs(1)

  • pbputs(1)
  • User command
  • linux

Encrypt and Share Files Safely with pbputs

You will finish with a checked workflow for sending a file, directory or standard input through pbputs, the encrypted companion to pbput. The receiver will use pbget to recover the content. This guide describes the installed pastebinit package, version 1.6.2-1, and its local pbputs(1) manual page.

Allow about fifteen minutes, plus the time needed to exchange a passphrase or prepare a GPG key. You need a shell, the pastebinit package and either a shared passphrase or a recipient key in your GPG keyring. The examples upload to the default paste service, so replace every placeholder and remove secrets you did not intend to share before running them.

1. Check the installed command

Confirm the executable and package version first. These are ordinary, read-only commands and do not need elevated privileges:

$ command -v pbputs
/usr/bin/pbputs
$ dpkg-query -W -f='${Package} ${Version}\n' pastebinit
pastebinit 1.6.2-1

The manual page documents no general option parser for pbputs. Its interface is a possible input filename followed by a possible GPG user. Do not copy flags from an unrelated paste client and assume they apply here.

Checkpoint: decide whether your input is a single file, a directory tree or text arriving on standard input. That choice changes the form of the command, but not the encryption step.

2. Encrypt one file with a passphrase

For a file that does not need public-key management, pass its path and answer the prompt interactively:

$ pbputs ./REPORT_FILE
Enter passphrase:
http://pastebin.com/PASTE_ID

Replace REPORT_FILE with a real path. The command compresses, encrypts and base64-encodes the data before uploading it. The manual describes LZMA compression and GPG encryption, with the paste service at http://pastebin.com by default. The URL is the value the recipient needs for retrieval; the passphrase is a separate secret that must reach them through a channel you trust.

Do not put the passphrase in the command line. Command lines can be exposed through shell history, process inspection or logging. If the file contains credentials, private keys or personal data, check the path carefully before pressing Enter. An encrypted upload is still an upload to a third-party service, and this command does not give you a local copy of the remote paste.

3. Encrypt for a GPG recipient

When the recipient has a suitable public key in your keyring, give the GPG user as the second argument:

$ pbputs ./REPORT_FILE RECIPIENT_KEY
http://pastebin.com/PASTE_ID

Use the recipient identifier accepted by your local GPG keyring, such as the key's email identity or fingerprint. Verify that it selects the intended key before uploading. The documented behaviour is to sign and encrypt to that recipient. The recipient can decrypt with their private key, while you do not need to transmit a shared passphrase.

This mode is not a way to discover or create keys. If GPG reports an ambiguous, missing or untrusted key, stop and resolve that separately. Do not replace the identifier with a guessed email address and continue with a sensitive file.

4. Send standard input

To encrypt text or another command's output, pipe it to pbputs. With standard input there is no filename argument:

$ printf '%s\n' 'MESSAGE_FOR_RECIPIENT' | pbputs
Enter passphrase:
http://pastebin.com/PASTE_ID

For recipient encryption, put the GPG user after the command in the pipeline:

$ some-command --report | pbputs RECIPIENT_KEY
http://pastebin.com/PASTE_ID

The manual distinguishes this from a filename or directory input: standard input is pasted directly on recovery, while a named file or directory is first archived with tar. The pipeline can therefore be useful for a report, but it is also easy to leak more output than intended. Review the producing command and its redirections before you run it.

5. Recover the upload with pbget

The recipient passes the returned URL to pbget. For a standard-input upload, recovery writes the plaintext to standard output:

$ pbget http://pastebin.com/PASTE_ID
MESSAGE_FOR_RECIPIENT

pbget prompts for the shared passphrase when passphrase encryption was used. For GPG-recipient encryption, the recipient's GPG setup supplies the private key needed for decryption. Keep the URL and secret separate when sending them to another person.

For a file or directory upload, give a destination directory when you want the archive extracted there:

$ mkdir -m 700 ./RECOVERY_DIR
$ pbget http://pastebin.com/PASTE_ID ./RECOVERY_DIR
INFO: Output is in [./RECOVERY_DIR]

Use a new, empty directory for an unfamiliar archive. Extraction can create paths and restore file attributes from the archive, so inspect the result before moving files into a live configuration directory. The command creates a temporary directory with mktemp when you omit the destination; record the reported location if you need to inspect recovered files later.

6. Diagnose the common mistakes

A prompt for a passphrase is normal when no GPG recipient is supplied. A missing passphrase or a wrong one means the recipient cannot decrypt the content; rerun the upload with the intended secret rather than sending the passphrase in a command-line argument.

If a file is not found, check the path and current directory without using sudo:

$ pwd
$ test -r ./REPORT_FILE && printf '%s\n' 'input is readable'
input is readable

Elevated privileges are not part of the normal workflow. Use them only when the source genuinely requires privileged read access, and remember that root access can expose more data than the intended report. Never use pbputs /etc/shadow as a test; the manual's example is a warning about capability, not a safe demonstration.

If recovery fails, preserve the URL, confirm whether the upload used a passphrase or a GPG recipient, and retry with the matching method. For an extracted archive, use a disposable destination and remove only that test directory after checking it. Do not delete the original input or overwrite an existing recovery directory while troubleshooting.

Done means

  • You confirmed the installed pbputs and package version.
  • You chose passphrase encryption or verified the intended GPG recipient.
  • You reviewed the input path or pipeline before uploading.
  • You recorded the returned URL without putting the passphrase in shell history.
  • The recipient recovered the expected plaintext or archive in a controlled destination.