5 ms·
In what scenario is it an advantage to be able to encrypt/decrypt data with a certain key, but not know the key directly?
by mfukar 9y ago
In what scenario is it an advantage to be able to encrypt/decrypt data with a certain key, but not know the key directly?
- viraptor 9y agoAny scenario where the key is not ephemeral and you're handling client's input (can expect exploitation). If you have a good enough separation/sandboxing, any exploit wouldn't be able to steal the encryption key, or other private data, even if the exploit worked. For handling encrypted secrets, this is popular as a HSM idea. You authenticate to a black box which does the crypto for you, but the key can't be extracted. Sometimes HSMs even have a physical tampering / self destruction protection.