From: Brian Candler Date: 2009-09-14T17:44:31+09:00 Subject: Re: Password on code - what's the best way to obfuscate it? Rodrigo Bermejo wrote: > I've been in the need to crate applications which require to make use of > another program which requires authentication. As everyone who has > tried to solve this problem with a script lang (no compiled, what would > be the best term /?), a security concern comes in play. > > Where in hell should I put the password /? Option 1: put the password in a config file, and use filesystem permissions to ensure it is readable to the application but not to anyone else. Of course, don't put the config file with the live password in your source repository. You can keep a file with dummy passwords in source, say config/database.yml.sample Then when the software is deployed, you do cp config/database.yml.sample config/database.yml chmod 400 config/database.yml vi config/database.yml (or the equivalent from your automated deployment process) to insert the real password(s). Option 2: GPG-encrypt your config file. When the application starts up, make it prompt the user for the passphrase to decrypt the config. This is most easily done by piping the config in on stdin, because gpg itself will prompt for the necessary passphrase. # startup script gpg --homedir /path/to/config --decrypt /path/to/config.yml.asc | ruby myapp.rb # application secret_data = YAML.load($stdin.read) This is very secure if your passphrase is random enough, but has the downside that if your machine reboots, it will have to wait for a passphrase before the application can start. -- Posted via http://www.ruby-forum.com/.