From: Michael Morin Date: 2008-07-01T02:36:52+09:00 Subject: Re: Hiding a password in code. Dana Merrick wrote: > Hello! > > The other day I wrote a small Ruby app to check my finances on Mint.com. > My intentions were to have this script run every once and a while and > display the information on my desktop (via a tool like Conky or GeekTool). > > My problem is, how do I handle my password? Here are the two situations > I've considered: > > 1) Use the command line to enter the password. > 2) Have the password stored in the script via some sort of encryption. > > Neither of these seem very secure. In the first option, someone can > sniff my password via the "ps" utility, and in the second, someone could > view the source code and figure it out. > > Security isn't a HUGE priority, as this account doesn't really have > access to anything serious. Right now, I have the password in the file, > encrypted with ROT13 (hah!), just to make it a little harder for someone > skimming the source to figure it out. > > Any ideas on how to handle this situation? > > -Dana > > Store your password in an encrypted file. When you start the script up, enter the encryption password to decrypt the file so your Ruby script can grab it and keep it in memory. It won't be stored in plaintext in the file (but will probably end up in swap if you're really paranoid). This is about as effective as entering the password as the script starts come to think of it. This has always been a problem. You can't store the password to be retrieved automatically, the best you can do it obfuscate it. And you're right, never give passwords on the command-line. Scripts that need passwords should read them from keyboard or STDIN. Especially if you're on a shared machine. -- Michael Morin Guide to Ruby http://ruby.about.com/ Become an About.com Guide: beaguide.about.com About.com is part of the New York Times Company