How to convert SecureString to System.String?

Use the System.Runtime.InteropServices.Marshal class: String SecureStringToString(SecureString value) { IntPtr valuePtr = IntPtr.Zero; try { valuePtr = Marshal.SecureStringToGlobalAllocUnicode(value); return Marshal.PtrToStringUni(valuePtr); } finally { Marshal.ZeroFreeGlobalAllocUnicode(valuePtr); } } If you want to avoid creating a managed string object, you can access the raw data using Marshal.ReadInt16(IntPtr, Int32): void HandleSecureString(SecureString value) { IntPtr valuePtr = IntPtr.Zero; try { valuePtr … Read more

When would I need a SecureString in .NET?

Some parts of the framework that currently use SecureString: WPF’s System.Windows.Controls.PasswordBox control keeps the password as a SecureString internally (exposed as a copy through PasswordBox::SecurePassword) The System.Diagnostics.ProcessStartInfo::Password property is a SecureString The constructor for X509Certificate2 takes a SecureString for the password The main purpose is to reduce the attack surface, rather than eliminate it. SecureStrings … Read more

Encrypt & Decrypt using PyCrypto AES 256

Here is my implementation and works for me with some fixes and enhances the alignment of the key and secret phrase with 32 bytes and iv to 16 bytes: import base64 import hashlib from Crypto import Random from Crypto.Cipher import AES class AESCipher(object): def __init__(self, key): self.bs = AES.block_size self.key = hashlib.sha256(key.encode()).digest() def encrypt(self, raw): … Read more

Best way to use PHP to encrypt and decrypt passwords? [duplicate]

You should not encrypt passwords, instead you should hash them using an algorithm like bcrypt. This answer explains how to properly implement password hashing in PHP. Still, here is how you would encrypt/decrypt: $key = ‘password to (en/de)crypt’; $string = ‘ string to be encrypted ‘; // note the spaces To Encrypt: $iv = mcrypt_create_iv( … Read more

What’s the purpose of Django setting ‘SECRET_KEY’?

It is used for making hashes. Look: >grep -Inr SECRET_KEY * conf/global_settings.py:255:SECRET_KEY = ” conf/project_template/settings.py:61:SECRET_KEY = ” contrib/auth/tokens.py:54: hash = sha_constructor(settings.SECRET_KEY + unicode(user.id) + contrib/comments/forms.py:86: info = (content_type, object_pk, timestamp, settings.SECRET_KEY) contrib/formtools/utils.py:15: order, pickles the result with the SECRET_KEY setting, then takes an md5 contrib/formtools/utils.py:32: data.append(settings.SECRET_KEY) contrib/messages/storage/cookie.py:112: SECRET_KEY, modified to make it unique for the … Read more

JavaScript string encryption and decryption?

var encrypted = CryptoJS.AES.encrypt(“Message”, “Secret Passphrase”); //U2FsdGVkX18ZUVvShFSES21qHsQEqZXMxQ9zgHy+bu0= var decrypted = CryptoJS.AES.decrypt(encrypted, “Secret Passphrase”); //4d657373616765 document.getElementById(“demo1”).innerHTML = encrypted; document.getElementById(“demo2”).innerHTML = decrypted; document.getElementById(“demo3″).innerHTML = decrypted.toString(CryptoJS.enc.Utf8); Full working sample actually is: <script src=”https://cdnjs.cloudflare.com/ajax/libs/crypto-js/3.1.2/rollups/aes.js” integrity=”sha256-/H4YS+7aYb9kJ5OKhFYPUjSJdrtV6AeyJOtTkw6X72o=” crossorigin=”anonymous”></script> <br><br> <label>encrypted</label> <div id=”demo1″></div> <br> <label>decrypted</label> <div id=”demo2″></div> <br> <label>Actual Message</label> <div id=”demo3″></div>

How do you Encrypt and Decrypt a PHP String?

Before you do anything further, seek to understand the difference between encryption and authentication, and why you probably want authenticated encryption rather than just encryption. To implement authenticated encryption, you want to Encrypt then MAC. The order of encryption and authentication is very important! One of the existing answers to this question made this mistake; … Read more