Description
Storing a cryptographic key in a source-code constant or string argument makes rotation and secret management difficult. If the code is exposed, the key no longer protects the encrypted data.
Potential impact
Depending on how the key is used, exposure may allow decryption of stored data, token forgery, or message tampering.
Remediation
Load keys from a KMS or secret manager, separate them by environment, and rotate them regularly.
Examples
Before
php
<?php
// Class member excerpt
private const ENCRYPTION_KEY = "Paintbrush";
After
php
<?php
$key = getenv('ENCRYPTION_KEY');
Explanation:
- Before: The cryptographic key is stored directly in the source code.
- After: The example reads a deployment-supplied key from an environment variable. Stop processing if it is missing or malformed, and restrict access to both the environment variable and the system supplying it.