Store API Credentials Safely: Obfuscation Before Encryption is Key

The challenge is that we can’t use hashing, as we would do for user passwords. We need the credentials to access the API, hence we need to reveal them upon retrieval from store. Encryption alone has its risks, however. In the simplest case, a mindless user chooses the word ‘*password* for the password and suddenly the potential hacker may have an easier task because they only need to try until *password* is revealed. One solution is to obfuscate the credentials characters among a larger string — like spreading some pepper in a plate.

image
Miguel Hacker Noon profile picture

Miguel

Scientist by training, creative spirit by choice.

Tags

Join Hacker Noon

Create your free account to unlock your custom reading experience.



Store API Credentials Safely: Obfuscation Before Encryption is Key
Source: Super Trending News PH

Post a Comment

0 Comments