DiskCryptor v2.0.2

DiskCryptor version 2.0.2 marks the first stable release of the 2.x series, bringing together the major architectural improvements introduced in 2.0 with further performance gains, expanded ARM64 support, and important bootloader and reliability fixes. Following the initial beta releases, the new generation is now ready for stable use. Users running DiskCryptor 2.0.0 or 2.0.1 should upgrade.

All use of DiskCryptor remains at the user’s own risk. Before encrypting a volume or changing its configuration, always have a current backup on hand and verify that it can be restored. Strong encryption provides no backdoor or password reset: even a small user error, lost authentication material, damage to critical volume metadata, power loss, or hardware failure can result in permanent data loss. In the most cases recovery without backups will be impossible.

The 2.x series introduces Argon2id key derivation, providing a modern, memory-hard option for protecting volume passwords against cracking attacks. The new Version 2 volume header format adds independent key slots, allowing multiple passwords and keyfiles to unlock the same volume. Header and volume layout editors provide greater control over existing volumes, including resizing headers, managing optional backup headers, and changing relocation areas.

Optional TPM integration in the DCS bootloader enables hardware-backed authentication and unattended system unlock configurations. Together with optional Secure Boot support, it brings modern platform security features to DiskCryptor’s boot architecture. TPM and Secure Boot functionality require a DiskCryptor Pro Supporter Certificate, available from the Xanasoft web shop.

Version 2.0.2 further strengthens boot management. A new Boot Menu Lock driver prevents Windows from changing the boot order away from DCS. TPM handling has been improved by correcting the default PCR mask and adding a workaround for issues affecting some ARM64 devices. The new TpmKill option allows DCS to entirely block access to the TPM before handing control to the operating system.

The pre-boot interface now includes a full touch console, extending the on-screen keyboard support introduced in 2.0. The recovery menu has been reworked and expanded, communication between DCS modules has been redesigned, and the bootloader now accepts passwords up to the intended limit of 128 characters. Image verification for DcsLdr has been delegated to shim’s verification service, substantially reducing the size of DcsLdr.efi. New commands also allow shim to be installed or removed independently of the DCS loader.

These improvements build on USB keyfile support, a pre-boot configuration menu, and the option to install DCS on a dedicated EFI System Partition. The bootloader can also pass derived header keys directly to the Windows driver, avoiding a redundant key derivation during startup.

Encryption performance has improved by approximately 25% overall, with up to around 60% higher throughput for some ciphers. Version 2.0.2 also adds hardware cryptography support on ARM64. The broader 2.x improvements include skipping unused sectors during encryption and decryption, removing SSD chunking that reduced performance on modern drives, and an asynchronous volume processing engine that resolves low-memory deadlocks and re-encryption race conditions.

Storage protection and usability have received substantial updates as well. Optional backup headers provide additional recovery options, while RAW volume protection helps prevent accidental writes or formatting of volumes without a recognized file system. Secure desktop password entry, virtual keyfiles, integrated TPM management, password caching controls, and a reorganized interface make both everyday use and advanced configuration easier.

This final release also fixes the hibernation issue introduced in Version 1.4.0, removing the need to use the legacy handoff workaround available in 2.0.1. Further corrections address default boot-volume presets on MBR systems and unwanted status output when no prompt is enabled. It includes the earlier 2.0.1 fixes for ARM64 crashes and bootloader compatibility, volume resizing, backup-header corruption, storage-file handling, and keyslot initialization.

DiskCryptor 2.0.2 completes the transition to the new 2.x generation, combining modern key derivation, flexible authentication, improved boot security, and faster encryption with the lightweight design and control over encrypted storage that define the project.

Download: https://github.com/DiskCryptor/DiskCryptor/releases/tag/v2.0.2