From: Dana Merrick Date: 2008-07-01T05:04:12+09:00 Subject: Re: Hiding a password in code. --------------enig79F6163F1F120717457B8DD2 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: quoted-printable Leslie Viljoen wrote: > "Interpreted language" is pretty much irrelevant though. The hackers > that be can pull hardcoded passwords out of compiled code very quickly > and easily. That's sort of true. If I didn't employ any string obfuscation, it would = be easy=20 for them to get the sensitive data. It would be much easier, however, to = obfuscate the password in compiled code so that it would be unreadable (w= ithout=20 significant means), than it would in a language where the source is readi= ly=20 available. In any case, I'm not particularly worried about hackers anyway. As I said= , this=20 isn't really dangerous information, I'd just rather it not be in plaintex= t. :-D. > Gnome solves this situation by using the Gnome login to open an > encrypted keyring which stores passwords to things like Wireless > networks. There should be a way for a Ruby program to leverage this > functionality. While this would be cool, I don't use Gnome so unfortunately it would be = useless=20 to me. I could, however, look into a Ruby API that works with OS X's Keyc= hain.=20 That's a good idea and I'll look into it. -Dana --=20 Dana Merrick - System Administrator Integrated Computer Solutions, Inc. 54B Middlesex Tpke, Bedford, MA 01730 617.621.0060 x112 - http://www.ics.com --------------enig79F6163F1F120717457B8DD2 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (Darwin) iEYEARECAAYFAkhpPN4ACgkQ7b+8UB5G/wM+gQCgkUm67q6MPis0/UY9JJ7yhPfZ RIgAnR8eEHE1YhLYcsjo7zv5ZZ/6fjOJ =4PFs -----END PGP SIGNATURE----- --------------enig79F6163F1F120717457B8DD2--