From: Guest Date: 2006-05-23T22:04:37+09:00 Subject: Re: Writing a interpreter extension Bira wrote: > On 5/23/06, Kris wrote: >> > Keeping your sensitive *data* encrypted on the other hand can be done >> > in software and with proper encryption, there is no need to obscure >> > the encryption routine, only the keys you're using (granted, you need >> > to find a secure way of destributing encryption passwords to users). >> > You could use the `openssl` ruby library to do the encryption, for >> > example. Openssl, by the way, is open source, yet quiete a few banks >> > trust it to protect their homebanking sites. >> >> How do those banks prevent the keys being found by their own staff or >> server admins? > > I'm no expert, but I know encryption keys aren't present in the source > code of the program. Wheter a given encryption program is secure or > not doesn't have anything to do with wheter it is open source or not. > A lot of encryption protocols involve keys generated on the spot from > other information, for example. An open source project compiled (open at design time) and software that has interpreted open source (open at run time) are different. And interpreted is less secure than compiled. Not much more secure in skilled hands, but even so. Its easier to write anti-tamper with compiled. Or better still as suggested using hardware. -- Posted via http://www.ruby-forum.com/.