i'm obviously missing something here.
could you explain why it is a bad idea to have two files, the key and salt, which
would be used to initially mount the regular file, then securely deleted from the
host and only re-introduced to the host when decryption/remounting is required.
and also, for us luddites, how do you read the password on stdin.
in great expectations,
poncenby