Похожие чаты

Hey guys, i'm a web developer and i'm currently working

on a pure PHP script that acts like a file manager / analizer for servers, and have access to the complete file system of the server where is installed; So, for such reason i made a "security key", basically a javascript auth function executed with Tampermonkey ( a browser extension), and the script will work only if the key is present

But i was thinking that maybe someone on the staff of the IT of a company or a sys-admin on a college that uses my script may want to use the app in a computer that doesn't have the "key" installed, so my question is:

Its a good idea to implement a master password to unlock the script withouth the key?

NOTE: is important to say the authentication process and all the AES decryption keys are contained in the "key", programmed to run from the Tampermonkey extension, and this information is totally isolated from the main php file of the utility, so no cookies or login information will be saved on the server or the local storage of the browser

1 ответов

11 просмотров

It depends on the type of script you are developing. If its open source, then the best idea i think is to not provide master key, as it may fell into wrong hand. If its private, then its your choice. Filesystem is the last place that anyone hacker will want have access to. Just consider the risks.

Похожие вопросы

Обсуждают сегодня

30500 за редактор? )
Владимир
47
а через ESC-код ?
Alexey Kulakov
29
Anyone knows where there are some instructions or discort about failed bridge transactions ?
Jochem
21
Чёт не понял, я ж правильной функцией воспользовался чтобы вывести отладочную информацию? но что-то она не ловится
notme
18
Привет)) уже кажется эту тему перемусолили, но вот я так и не понял. Я сейчас сижу на 27дюймов 2к мониторе. На Актуальной макоси, если я куплю 27д 4к монитор: - будет ли изобр...
Vladislav Piskunov
16
Also, why can’t the community have a vote/ say when it comes to initiatives like buybacks. Isn’t the point of crypto decentralisation? Don’t we deserve input as long term supp...
👨🏽‍🦰
13
any reference of this implementation?
BitBuddha
29
Страшнейшая правда про списки ЦБ. С первых дней жизни P2P сферы, молодые человеки, начитавшись законодательной базы и "внутренних" документов, решили, что им противостоит сер...
Foxcool
3
У меня есть функция где происходит это: write_bit(buffer, 1); write_bit(buffer, 0); write_bit(buffer, 1); write_bit(buffer, 1); write_bit(buffer, 1); w...
~
14
Hi guys, any problem with Pulsebrige? Trying to transfer from wETH to ETH. First it tells me to connect my metamask "through mobile app" not desktop. Then I did and confirmed ...
Snowflakecrypto
13
Карта сайта