Hardcoded cryptographic key

Hardcoded cryptographic key

Description

Storing a cryptographic key in a source-code constant or string argument makes rotation and secret management difficult. If the code is exposed, the key no longer protects the encrypted data.

Potential impact

Depending on how the key is used, exposure may allow decryption of stored data, token forgery, or message tampering.

Remediation

Load keys from a KMS or secret manager, separate them by environment, and rotate them regularly.

Examples

Before

php
<?php
// Class member excerpt
private const ENCRYPTION_KEY = "Paintbrush";

After

php
<?php
$key = getenv('ENCRYPTION_KEY');

Explanation:

  • Before: The cryptographic key is stored directly in the source code.
  • After: The example reads a deployment-supplied key from an environment variable. Stop processing if it is missing or malformed, and restrict access to both the environment variable and the system supplying it.

References