From: Michael Morin Date: 2008-07-01T06:13:19+09:00 Subject: Re: Hiding a password in code. Leslie Viljoen wrote: > On 6/30/08, Dana Merrick wrote: >> Michael Morin wrote: >> >>> Store your password in an encrypted file. When you start the script up, >> enter the encryption password to decrypt the file so your Ruby script can >> grab it and keep it in memory. It won't be stored in plaintext in the file >> (but will probably end up in swap if you're really paranoid). >>> This is about as effective as entering the password as the script starts >> come to think of it. This has always been a problem. You can't store the >> password to be retrieved automatically, the best you can do it obfuscate it. >> And you're right, never give passwords on the command-line. Scripts that >> need passwords should read them from keyboard or STDIN. Especially if >> you're on a shared machine. >> These are excellent points. The reason I haven't done this is that I'd like >> to have my script be able to run without action from me, in the background. >> >> I suppose I just need to accept the fact that I'm asking to do something >> inherently insecure in an interpreted language. I'm pleased enough with this >> solution: >> >> form['password'] = @options[:pass] || >> "AvprGel".tr("A-Za-z","N-ZA-Mn-za-m") > > "Interpreted language" is pretty much irrelevant though. The hackers > that be can pull hardcoded passwords out of compiled code very quickly > and easily. > > Gnome solves this situation by using the Gnome login to open an > encrypted keyring which stores passwords to things like Wireless > networks. There should be a way for a Ruby program to leverage this > functionality. > > Les > Come to think of it, I used to use KDE's KWallet via dcop to store passwords. It of course has all the same weaknesses, but you only need to decrypt your passwords once when you boot up. Be aware that any program can now read your passwords. Specifically with KWallet, it had no way of authenticating which program was requesting the passwords. You could easily write a Ruby script that pretends to be Kopete or Konqueror and read any password. Using something to display a dialog box to enter your password when the script starts would be the best solution. It's not very inconvenient to enter your password once when it starts up, and the password doesn't have to be stored anywhere. -- Michael Morin Guide to Ruby http://ruby.about.com/ Become an About.com Guide: beaguide.about.com About.com is part of the New York Times Company