From: Mark Probert Date: 2002-04-16T23:12:32+09:00 Subject: Re: crypting ruby source At 09:23 AM 4/16/2002 +0900, Booker wrote: >-----BEGIN PGP SIGNED MESSAGE----- > > >> > >> There are other reasons as well. I want to be able to distribute > >> data collection on customer sites. One of the requirements is that > >> I be able to get into various boxes that require a fixed password. > >> This based on the date of the box, and then apply the date to an > >> algorithm to generate the password. And I don't want the customer to > >> have that password algorithm ... > >> > >=- Security through obscurity never works in the long run. If >your algorithm can't be public, it can't be secure. > There are some unfortunate realities that come with my particular problem, one of them is that the password algorithm is not really secure. On the other hand, our average customer is not interested in getting this level of access to our boxes, so we rely on a combo of disinterest and obscurity. The idea I would like is not true encryption, a la PKI, rather an in-built mechanism to discourage casual viewing of the source. That could be byte-code, crypted source, or whatever, it doesn't really matter. As you say, this is not a solution for -real- security, just a convenience. Regards, -mark.