Re: embedding passwords/other sensitive strings into a C++ program
From: David Lindauer (camille_at_bluegrass.net)
Date: 11/17/04
- Next message: Old Wolf: "Re: Function to do nothing"
- Previous message: Robert Gamble: "Re: C/C++ code beautifier"
- In reply to: J.Steiner: "embedding passwords/other sensitive strings into a C++ program"
- Next in thread: Michiel Salters: "Re: embedding passwords/other sensitive strings into a C++ program"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Tue, 16 Nov 2004 23:39:05 GMT
"J.Steiner" wrote:
> Just curious if anyone has any thoughts about what best practice would
> be for something like this...
>
> We want to write a program that will send the user (via email) a
> password when they click a button. Also, it will send the email to a
> support team who will log that the password has been requested so they
> can then change the password (and recompile the program). Seems
> simple enough.
>
> The problems I can think of are:
>
> 1. how do you encrypt this password from casual viewing (executing
> unix commnand: strings <exe name>) for example. I suggested using the
> ascii code to print the string. seems simple enough.
>
> 2. how do you encrypt this password from more aggressive viewing, ie
> someone looking at the source code, pulling the project files out of
> the repository (we use cvs, for example). My thought was to either
> put the password as a build option on the compiler (which would
> necessitate adding an option before each compile), or to put the whole
> project into cvs as a zip file with the password on it, assuming that
> the support staff will know that password.
one solution is to write a utility that generates a 'scrambled' password;
optionally it can embed the byte codes into the program so it will be
accessible on the next compile (or even modify the EXE version of the file
and obviate a compile). Your program then unscrambles it prior to
emailing it. This is harder to break, although obviously anyone who has
unlimited access to your source code (and many others who don't) and who
has time on their hands will break this scheme too.
David
- Next message: Old Wolf: "Re: Function to do nothing"
- Previous message: Robert Gamble: "Re: C/C++ code beautifier"
- In reply to: J.Steiner: "embedding passwords/other sensitive strings into a C++ program"
- Next in thread: Michiel Salters: "Re: embedding passwords/other sensitive strings into a C++ program"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|