3 ms·
With java theres a GuardedString implementation https://docs.oracle.com/en/middleware/idm/identity-governance/12.2.1.3/omicf/org/identityconnectors/common/secu
by CraigJPerry 1y ago
With java theres a GuardedString implementation https://docs.oracle.com/en/middleware/idm/identity-governance/12.2.1.3/omicf/org/identityconnectors/common/security/GuardedString.html https://docs.oracle.com/en/middleware/idm/identity-governanc...
- antonvs 1y agoThose are primarily for in-memory security. They apparently uses a "known default key" in its serialized form. At least when it comes to logging, that's more like obfuscation than security.
- otterley 1y agoAccording to its documentation, you can’t directly log a GuardedString because it doesn’t implement the toString() method. You have to pass it an accessor instance through its access() method to extract the plaintext.
- otterley 1y agoIt doesn't look like it's a part of the standard API though. That looks like it's some sort of framework API for Oracle Fusion. It's also not open source.