Description
Writing passwords, tokens or private keys to files or other storage without encryption or equivalent protection exposes the secrets if someone gains access to that storage.
Potential impact
- Stolen credentials can enable account takeover and reuse of long-lived tokens.
Remediation
Use encryption with appropriate key management or a dedicated secure store. If a token is used only for verification and its original value is never needed again, consider suitable hash-based storage.
Examples
Before
const char *token = getenv("API_TOKEN");
fprintf(file, "%s", token);
After
const char *token = getenv("API_TOKEN");
char *sealed = encrypt(token);
fprintf(file, "%s", sealed);
The first excerpt writes the environment-variable token directly to a file. The second protects the value before storage.
encrypt is an illustrative helper whose implementation is omitted. Implement validated authenticated encryption and key management. To store the result with %s as shown, encode it as a null-terminated string. Also handle a missing environment variable, encryption failure and file-write errors.