4 ms·
What data are you trying to protect? There are a number of different approaches to this, all of which vary by what you're trying to achieve. You can encrypt cer
by Firehed 15y ago
What data are you trying to protect? There are a number of different approaches to this, all of which vary by what you're trying to achieve. You can encrypt certain fields generating an encryption key based on non-encrypted data in the row (ex. your key may be sha256(primary key value + create time + application secret), and rather than protecting one master key you must protect the key-generation algorithm). Or you can have one master key that you use to encrypt data - this key should never be written to disk (the key should be decrypted into memory from your key custodians' passwords). Or a combination of both. You should also have a way to version keys so that you can perform key rotation. Certain DB engines allow the entire database file to be encrypted (SQLite offers this with some paid extension, I believe). Or have the user encrypt the data before sending it (as some backup services do).
Consult an expert. I could give more details about effective encryption strategies, but I don't want a newbie finding my post, reading half of it, and implementing something dangerously bad. At least no encryption is at a known level of safety; data that's been encrypted incorrectly gives a huge false sense of security.