Description
Keys embedded in source code may be disclosed with the code. Hardcoding also makes rotation difficult and can encourage reuse of the same key across systems.
Potential impact
- Key exposure: A leaked key can allow an attacker to decrypt protected data.
- Data disclosure: Sensitive information may be exposed.
- Wider compromise: Reusing a key across systems increases the impact of its exposure.
Remediation
- Supply keys through environment variables rather than embedding them in source.
- Store keys securely and restrict access.
- Use a vetted cryptographic library for key handling.
Replace exposed keys. These examples focus on where keys come from. CBC needs separate authentication protection; prefer authenticated encryption when designing a real system.
Examples
AES encryption
Before
python
# AES with a hardcoded key
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad
cipher = AES.new(b'This is a key123', AES.MODE_CBC) # Hardcoded key
plaintext = b'This is a secret message.'
ciphertext = cipher.encrypt(pad(plaintext, AES.block_size))
After
python
# AES with a key supplied through the environment
import os
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad
key = os.environ['ENCRYPTION_KEY'].encode() # Read the key from the environment
cipher = AES.new(key, AES.MODE_CBC)
plaintext = b'This is a secret message.'
ciphertext = cipher.encrypt(pad(plaintext, AES.block_size))
Explanation
- Before: The encryption key is embedded in the source and may be exposed with it.
- After: The key is supplied through the environment, reducing exposure through source code.
RSA encryption
Before
python
# RSA with a hardcoded private key
from Crypto.PublicKey import RSA
from Crypto.Cipher import PKCS1_OAEP
# Public documentation fixture: never use this key in a real system.
private_key = RSA.import_key('''-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEAsyDriTGA+qrcwgMnd8+ax64xbWYiaxv0pMFuvolq742Zw+x1
dCw27Cotr+VjoymdHNAmxefWNvxOd32CIHmSv5cN6I+UbodLxjp0vLBrsa7krIs7
zD+m4EL6Ebu25YNJkYVFMkqvLBXRZlj41LZY8CQr1LOKXq/NIKhSSmEjKSgtGZnS
zETsi6gKwKp9LEsPGtlylh52+psI6zimj2sVAd/Wz6RoenAZ8K4i43Nto3VmjmtJ
hctt0nwnvIYaLKBOC6rs+XTfZDhaDKbUwoOCzPf8F5O4i5LbdQh8D/n05uk7kanB
yo7CSMW6RKUuR/upxanu7iRrfSNC5dWbknQuDQIDAQABAoIBAFBO5ApgHVlEnTCG
RX2bn+MCH7rSXX/zypzK9CGMblrz+woxyv7Ii98Zkd4YU7FlCMFQOPHlXM7OE0fT
BzIUD0zCJkQrivp6wegfcRLfbYj9xhvtWGPb7a8BmCe3JuqDD8qkGz/O5/Y12emu
3fBPyFPxg40a6WBGJQsNK8eZATCDx//RsksJUmEuKlZ4qiDKO7P7+x1tfN9oWl8x
qkINbCRplM139lUnFTUJmLDGricM45y98Dd8kfgtBa66cznAibpVScWJYJbwgyT3
H1k70uST3vaSdvP+tWsb4AR/IdxhpUXGvh64OfpjfVMg+Rol7jPfkiV10hJBrS13
bX0vyakCgYEAxX+NcZp5by1MKgP/FHH/Nn+uLB4DBTMN2Eq9/LAA3rd6uW0659ed
HdTiD7l6L1uij0W7I7jB9Q5DFWKaAbLzdkkezH9yK3gV4m+RfWpRNjiQ+d4j39pb
Wz1lmMOYeQKORA/+avSCSmuSEcsLZpp9t5NA/ZIqfkY8ZnMH6B+nNXMCgYEA6DBh
yB8Q0GFDpJztwrxiWxHo+oQXPgR+5yEmVAlYACaNiBt3N9tbpqKB+8IR7WSi8xS/
BVMV5qVjas5TB3vJJYXhQAtvVUfw0iTy3txOs6qPpjaREFiBfsXIiO0AElB34QPb
J/LMSJU9Egi7djP9z/UOZieCCtZdsQOJGvgCLn8CgYEAxRUXGdGT8pzaT2czibyE
eGcLcNz2GJ8s5rUXR+x+wcGIxzc4PBlOoXFJsXVed5nS63QjXm9Fpfx4dwOxOZbR
Gy22fU2EqdooxJCfN+77Yccq7R1+4SiuV6s6EirFoaQqQcNQGH0s84TK+9SJ6Pas
E5/vj9rnaqE+LuIFdt73Zf8CgYEAjhY1cEqadnpe85hY40d3BPYD1XIJ6xjDM9uU
Ye7J3GW7TKRKI3NoNaPS2Waco+Jm2UxDzRVYHKnvGcgjBTxaDk1MV23n9o8srtyP
h5PX0Zi5iWRxB0iyDgsouaoW1h5KDffXIC4zluNE2Qlg9mfAlYcIBbl9mfYupYld
WJSWeS8CgYBx+B5Nm9LGajLalADzuoBie7q+SpIxuOMekX3P5kUWva6RkLrx7SQK
+9T251RMzP3As3OnGCToiXn4mpGFSIy4yK4SxN4NCd+ZZJHs/hSzQLn5K3rkNJP/
bpfhw/iskUP1xeLZjp+yBRCmTGWN+HKf2B3/wCa2fQjIh+TeLB5SHg==
-----END RSA PRIVATE KEY-----''')
cipher = PKCS1_OAEP.new(private_key)
ciphertext = cipher.encrypt(b'This is a secret message.')
After
python
# RSA with a private key supplied through the environment
import os
from Crypto.PublicKey import RSA
from Crypto.Cipher import PKCS1_OAEP
private_key = RSA.import_key(os.environ['PRIVATE_KEY']) # Read the key from the environment
cipher = PKCS1_OAEP.new(private_key)
ciphertext = cipher.encrypt(b'This is a secret message.')
Explanation
- Before: The RSA private key is embedded in the source.
- After: The private key is supplied through the environment instead of being stored in source code.