RE: Password Hiding

From: Michael Silk (michaelsat_private)
Date: Tue Jul 29 2003 - 16:02:36 PDT

  • Next message: Qin An: "[Q] cksum of UDP packet"

    You cannot.
    
    Make the user keep it on some external source that
    they must connect when the run your program. hiding
    the password is not possible (unless it is acceptable
    that their computer is compromised an the key
    is recovered).
    
    -- Michael
    
    -----Original Message-----
    From: pablo gietz [mailto:pablo.gietzat_private]
    Sent: Wednesday, 30 July 2003 4:14 AM
    To: secprog
    Subject: Password Hiding
    
    
    Hi all
    This is my first post,
    What can I do to hide a password that is used to encrypt-decrypt a
    config.file? .
    Where to save the password?. The program must run without user
    intervention and use this password to access that file.
    
    Language: Delphi
    
    Platform: windows
    
    Thanks
    
    --
    Pablo A. C. Gietz
    Jefe de Seguridad Informática
    Nuevo Banco de Entre Ríos S.A.
    Te.: 0343 - 4201351
    
    
    La información y archivos contenidos en este mensaje son confidenciales y para utilización exclusiva de los destinatarios consignados. Si Usted no reviste ese carácter, no se encuentra autorizado para divulgar, copiar,distribuir o retener todo o parte de la informacion y archivos, y deberá notificarlo de inmediato al remitente y eliminarlo de su sistema. Muchas gracias.
    
    
    
    
    
    CAUTION: This email message and accompanying data may contain information that is confidential and/or subject to legal privilege. If you are not the intended recipient, you are notified that any use, dissemination, distribution or copying of this message or data is prohibited. If you have received this email message in error, please notify us immediately and erase all copies of this message and attachments. Thank you.
    
    This email is for your convenience only, you should not rely on any information contained herein for contractual or legal purposes. You should only rely on information and/or instructions in writing and on company letterhead signed by authorised persons.
    



    This archive was generated by hypermail 2b30 : Wed Jul 30 2003 - 07:52:48 PDT