4 ms·
I have done something like this for embedding Easter eggs in websites where a user can just "view source" to see the code. I want someone who looks to know ther
by jstrieb 3y ago
I have done something like this for embedding Easter eggs in websites where a user can just "view source" to see the code. I want someone who looks to know there is an Easter egg, but not know what it does or how to activate it...
Code is AES-GCM encrypted, and the encrypted blob is stored on the web server. The "cheat code" to activate the Easter egg is the decryption key (the passphrase used with a key derivation function, to be precise). Entering the cheat code triggers an attempt to decrypt the blob. If the password is correct and the code decrypts successfully, the decrypted code is run with eval. If the passphrase is incorrect, nothing happens.
Thus, nobody inspecting the code can know what the cheat code is or what it does without breaking the crypto. But someone who knows it can enter it and trigger the magical cheat behavior.
Note that it's important to use authenticated encryption so that the user's browser doesn't try to execute garbled text when decryption fails.