Hardcoded cryptographic keys

Cryptographic keys embedded in source code

Description

Keys embedded in source code may be disclosed with the code. Hardcoding also makes rotation difficult and can encourage reuse of the same key across systems.

Potential impact

  • Key exposure: A leaked key can allow an attacker to decrypt protected data.
  • Data disclosure: Sensitive information may be exposed.
  • Wider compromise: Reusing a key across systems increases the impact of its exposure.

Remediation

  • Supply keys through environment variables rather than embedding them in source.
  • Store keys securely and restrict access.
  • Use a vetted cryptographic library for key handling.

Replace exposed keys. These examples focus on where keys come from. CBC needs separate authentication protection; prefer authenticated encryption when designing a real system.

Examples

AES encryption

Before

python
# AES with a hardcoded key
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad

cipher = AES.new(b'This is a key123', AES.MODE_CBC) # Hardcoded key
plaintext = b'This is a secret message.'
ciphertext = cipher.encrypt(pad(plaintext, AES.block_size))

After

python
# AES with a key supplied through the environment
import os
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad

key = os.environ['ENCRYPTION_KEY'].encode()  # Read the key from the environment
cipher = AES.new(key, AES.MODE_CBC)
plaintext = b'This is a secret message.'
ciphertext = cipher.encrypt(pad(plaintext, AES.block_size))

Explanation

  • Before: The encryption key is embedded in the source and may be exposed with it.
  • After: The key is supplied through the environment, reducing exposure through source code.

RSA encryption

Before

python
# RSA with a hardcoded private key
from Crypto.PublicKey import RSA
from Crypto.Cipher import PKCS1_OAEP

# Public documentation fixture: never use this key in a real system.
private_key = RSA.import_key('''-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEAsyDriTGA+qrcwgMnd8+ax64xbWYiaxv0pMFuvolq742Zw+x1
dCw27Cotr+VjoymdHNAmxefWNvxOd32CIHmSv5cN6I+UbodLxjp0vLBrsa7krIs7
zD+m4EL6Ebu25YNJkYVFMkqvLBXRZlj41LZY8CQr1LOKXq/NIKhSSmEjKSgtGZnS
zETsi6gKwKp9LEsPGtlylh52+psI6zimj2sVAd/Wz6RoenAZ8K4i43Nto3VmjmtJ
hctt0nwnvIYaLKBOC6rs+XTfZDhaDKbUwoOCzPf8F5O4i5LbdQh8D/n05uk7kanB
yo7CSMW6RKUuR/upxanu7iRrfSNC5dWbknQuDQIDAQABAoIBAFBO5ApgHVlEnTCG
RX2bn+MCH7rSXX/zypzK9CGMblrz+woxyv7Ii98Zkd4YU7FlCMFQOPHlXM7OE0fT
BzIUD0zCJkQrivp6wegfcRLfbYj9xhvtWGPb7a8BmCe3JuqDD8qkGz/O5/Y12emu
3fBPyFPxg40a6WBGJQsNK8eZATCDx//RsksJUmEuKlZ4qiDKO7P7+x1tfN9oWl8x
qkINbCRplM139lUnFTUJmLDGricM45y98Dd8kfgtBa66cznAibpVScWJYJbwgyT3
H1k70uST3vaSdvP+tWsb4AR/IdxhpUXGvh64OfpjfVMg+Rol7jPfkiV10hJBrS13
bX0vyakCgYEAxX+NcZp5by1MKgP/FHH/Nn+uLB4DBTMN2Eq9/LAA3rd6uW0659ed
HdTiD7l6L1uij0W7I7jB9Q5DFWKaAbLzdkkezH9yK3gV4m+RfWpRNjiQ+d4j39pb
Wz1lmMOYeQKORA/+avSCSmuSEcsLZpp9t5NA/ZIqfkY8ZnMH6B+nNXMCgYEA6DBh
yB8Q0GFDpJztwrxiWxHo+oQXPgR+5yEmVAlYACaNiBt3N9tbpqKB+8IR7WSi8xS/
BVMV5qVjas5TB3vJJYXhQAtvVUfw0iTy3txOs6qPpjaREFiBfsXIiO0AElB34QPb
J/LMSJU9Egi7djP9z/UOZieCCtZdsQOJGvgCLn8CgYEAxRUXGdGT8pzaT2czibyE
eGcLcNz2GJ8s5rUXR+x+wcGIxzc4PBlOoXFJsXVed5nS63QjXm9Fpfx4dwOxOZbR
Gy22fU2EqdooxJCfN+77Yccq7R1+4SiuV6s6EirFoaQqQcNQGH0s84TK+9SJ6Pas
E5/vj9rnaqE+LuIFdt73Zf8CgYEAjhY1cEqadnpe85hY40d3BPYD1XIJ6xjDM9uU
Ye7J3GW7TKRKI3NoNaPS2Waco+Jm2UxDzRVYHKnvGcgjBTxaDk1MV23n9o8srtyP
h5PX0Zi5iWRxB0iyDgsouaoW1h5KDffXIC4zluNE2Qlg9mfAlYcIBbl9mfYupYld
WJSWeS8CgYBx+B5Nm9LGajLalADzuoBie7q+SpIxuOMekX3P5kUWva6RkLrx7SQK
+9T251RMzP3As3OnGCToiXn4mpGFSIy4yK4SxN4NCd+ZZJHs/hSzQLn5K3rkNJP/
bpfhw/iskUP1xeLZjp+yBRCmTGWN+HKf2B3/wCa2fQjIh+TeLB5SHg==
-----END RSA PRIVATE KEY-----''')
cipher = PKCS1_OAEP.new(private_key)
ciphertext = cipher.encrypt(b'This is a secret message.')

After

python
# RSA with a private key supplied through the environment
import os
from Crypto.PublicKey import RSA
from Crypto.Cipher import PKCS1_OAEP

private_key = RSA.import_key(os.environ['PRIVATE_KEY'])  # Read the key from the environment
cipher = PKCS1_OAEP.new(private_key)
ciphertext = cipher.encrypt(b'This is a secret message.')

Explanation

  • Before: The RSA private key is embedded in the source.
  • After: The private key is supplied through the environment instead of being stored in source code.

References