Re: how do I protect/encrypt sensitive data in adatabase?
| From: | Chris Adams | Date: | Sun, 25 Jun 2000 23:22:41 +0000 |
| Subject: | Re: how do I protect/encrypt sensitive data in adatabase? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-3052@lists.php.net to get a copy of this message | ||
> I had designed a system which assumes that root on the webserver is not a
> bad person (I agree, get another job if this is a problem :)
I think that's the only alternative other than attempting to make the BOFH look friendly.
> It was originally psychotic:
> -user signs up, we generate a key, keep the public key, and show them their
> private key only once on a page which expires quickly (this is of course all
> over ssl). we tell them: "lose this, lose your data"
Why do I have this feeling that entirely too many people just wrote this on a sticky note on their
monitor?
> We'll be using GPG to create an encryption system which does this (as part
> of binarycloud (binarycloud.com) )... but gnuPG does _not_ allow the key to
> be passed on the command line, which is lame...
Can you use popen() to pass it on stdin to GPG? This would also have the advantage of not making
that info visible to everyone on the system who can run ps.
> so for the moment we're using it, but Chris: if you want to write a wrapper
> for OpenSSL, I'd kiss your feet :)
I'm working on it but I've got a lot of other stuff on my todo list.