paint-brush
Store API Credentials Safely: Obfuscation Before Encryption is Keyby@zapalote
2,071 reads
2,071 reads

Store API Credentials Safely: Obfuscation Before Encryption is Key

by Miguel Albrecht3mOctober 3rd, 2021
Read on Terminal Reader
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

The challenge is that we can’t use hashing, as we would do for user passwords. We need the credentials to access the API, hence we need to reveal them upon retrieval from store. Encryption alone has its risks, however. In the simplest case, a mindless user chooses the word ‘*password* for the password and suddenly the potential hacker may have an easier task because they only need to try until *password* is revealed. One solution is to obfuscate the credentials characters among a larger string — like spreading some pepper in a plate.

Companies Mentioned

Mention Thumbnail
Mention Thumbnail
featured image - Store API Credentials Safely: Obfuscation Before Encryption is Key
Miguel Albrecht HackerNoon profile picture
Miguel Albrecht

Miguel Albrecht

@zapalote

Scientist by training, creative spirit by choice.

About @zapalote
LEARN MORE ABOUT @ZAPALOTE'S
EXPERTISE AND PLACE ON THE INTERNET.
L O A D I N G
. . . comments & more!

About Author

Miguel Albrecht HackerNoon profile picture
Miguel Albrecht@zapalote
Scientist by training, creative spirit by choice.

TOPICS

THIS ARTICLE WAS FEATURED IN...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite
Buff
Ift
Mastodon
Newsbreak
Poast
Allella
Leftic
Bye
Accurate
Runonflux