Solved

Non-human readable file handling

Posted on 2004-08-15
5
404 Views
Last Modified: 2012-06-22
Hi,

I want to store a password (which the user has chosen to login to my program) in an external file.
However i don't want the external file to be readable in anyway, e.g. when opening the file in windows notepad it should not display the password text. I have tried binary files (FileOutputStream and DataOutputStream classes), although the text editor can't read the file properly it still displays the password text i have written to it.

Is there any way in java i can save a password in an external file and be 100% sure that the password cannot be retrieved unless read by my program. I was thinking along the lines of just saving it using some sort of java class rather than having to write some sort of complex algorithm which i write the password with then read it back by reversing the algorithm (not sure if that would make sense to experts!) but i hope you get the idea of what im trying to do.

Thanks !
0
Comment
Question by:Ravi Singh
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 86

Expert Comment

by:CEHJ
ID: 11803695
You should store the password in the file as an MD5 hash and then compare that to the MD5 hashed value of the input. The MD5 hash is unreadable and 'uncrackable'
0
 
LVL 18

Author Comment

by:Ravi Singh
ID: 11803738
Hi CEHJ where can I learn more about MD5? Is there any online tutorials? Thanks!
0
 
LVL 86

Expert Comment

by:CEHJ
ID: 11803745
See

http://javaalmanac.com/egs/java.security/Digest.html

You can write the byte buffer into the file
0
 
LVL 86

Accepted Solution

by:
CEHJ earned 50 total points
ID: 11803768
You can play with this: put it in a main method:

            String enteredPassword = args[0];
            java.security.MessageDigest md5 = java.security.MessageDigest.getInstance("MD5");
            // Just an example - all you'd be storing is 'digestedPassword' in a file
            String password = "abracadabra";
            byte[] digestedPassword = md5.digest(password.getBytes("UTF8"));
            byte[] enteredPasswordDigested = md5.digest(enteredPassword.getBytes("UTF8"));
            System.out.println(new sun.misc.HexDumpEncoder().encode(digestedPassword));
            System.out.println(new sun.misc.HexDumpEncoder().encode(enteredPasswordDigested));
            System.out.println(md5.isEqual(enteredPasswordDigested, digestedPassword)? "You're in!" : "No dice!");
0
 
LVL 86

Expert Comment

by:CEHJ
ID: 11804151
8-)
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction This article is the first of three articles that explain why and how the Experts Exchange QA Team does test automation for our web site. This article explains our test automation goals. Then rationale is given for the tools we use to a…
In this post we will learn how to make Android Gesture Tutorial and give different functionality whenever a user Touch or Scroll android screen.
Viewers will learn one way to get user input in Java. Introduce the Scanner object: Declare the variable that stores the user input: An example prompting the user for input: Methods you need to invoke in order to properly get  user input:
This video teaches viewers about errors in exception handling.
Suggested Courses

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question