RE: secure storage of sensitive data in J2EE
"Erez Metula" <[email protected]> Mon, 31 Jan 2005 08:59:41 +0200
| Newsgroups | gmane.comp.security.web-applications,gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
I think that the issue here is sensitive information stored on the server side like connection strings, encryption keys and such. You can't ask the user to enter a password for this kind of information. Storing this information in a file in cleartext, won't protect this information from someone who has access to the server, for example a legitimate (malicious) admin user or a hacker who had managed to break into the system. ---------------------------------------------------------------------------- -------------------------------------- Erez Metula Application Security Consultant Avnet Data Security Mobile: 972-54-8179538 Office: 972-3-9560074 (Ext. 126) -----Original Message----- From: Alexander Klimov [mailto:[email protected]] Sent: Tuesday, January 25, 2005 6:33 PM To: chaim moshe Cc: [email protected]; [email protected] Subject: Re: secure storage of sensitive data in J2EE On Tue, 25 Jan 2005, chaim moshe wrote: > where can I store sensitive data like encryption keys, passwords, > etc. in J2EE? surely, you can save it in the keystore, but the catch > is where do you store the keystore password to protect it from > external access? storing the keystore password in code or in config > files is not secured enough. Well, there is no way to make the following things simultaneously without additional input for legitimate user: -- a legitimate user is able to recover information -- an attacker is unable to recover information > In the .NET environment you have DPAPI that was designed exactly for this > kind of problem, the sensitive data is encrypted at the OS level with the > user/machine password and is decrypted at runtime. This is a solution: the legitimate user needs to enter password which is cached by the system. I really doubt that J2EE can have similiar things since many OSes do not cache user passwords. > What is the solution in the J2EE environment ? You can ask the user to enter the password. An alternative solution is to use non-owner-read-protected files. -- Regards, ASK This Mail Was Scanned By Avnet Secure System ************************************************************************************ This footnote confirms that this email message has been scanned by PineApp Mail-SeCure for the presence of malicious code, vandals & computer viruses. ************************************************************************************