From: Leslie Viljoen Date: 2006-05-23T22:23:05+09:00 Subject: Re: Writing a interpreter extension On 5/23/06, Guest wrote: > Tim Becker wrote: > >> How do those banks prevent the keys being found by their own staff or > >> server admins? > > > > That's a different problem, typically solved by using secure hardware. > > The point is, only the key needs to be secret, not the implementation. > > > > -tim > > Agreed, but how do you hide the key from people with access to the > server? You should read up on how SSL works: http://www.ourshop.com/resources/ssl.html The keys are not embedded in the program but are secured using the operating system. Private keys (certificates) are "signed" (encrypted) by a third party known to be reliable by both bank and client. Each private key is just a file on a harddrive, protected by the operating system. Someone who had physical access to that harddrive can get the key (if they can bypass the operating system) but we assume the bank keeps it physically secure. This is pretty similar to my SSH example at the beginning - keys are held in files apart from the source code, secured by the OS. With SSH you can also have a "key to a key" where the key file is itself encrypted and the user has to type a password to decrypt it before it can be used. Les