Solved

Non-human readable file handling

Posted on 2004-08-15
5
396 Views
Last Modified: 2012-06-22
Hi,

I want to store a password (which the user has chosen to login to my program) in an external file.
However i don't want the external file to be readable in anyway, e.g. when opening the file in windows notepad it should not display the password text. I have tried binary files (FileOutputStream and DataOutputStream classes), although the text editor can't read the file properly it still displays the password text i have written to it.

Is there any way in java i can save a password in an external file and be 100% sure that the password cannot be retrieved unless read by my program. I was thinking along the lines of just saving it using some sort of java class rather than having to write some sort of complex algorithm which i write the password with then read it back by reversing the algorithm (not sure if that would make sense to experts!) but i hope you get the idea of what im trying to do.

Thanks !
0
Comment
Question by:Ravi Singh
  • 4
5 Comments
 
LVL 86

Expert Comment

by:CEHJ
ID: 11803695
You should store the password in the file as an MD5 hash and then compare that to the MD5 hashed value of the input. The MD5 hash is unreadable and 'uncrackable'
0
 
LVL 18

Author Comment

by:Ravi Singh
ID: 11803738
Hi CEHJ where can I learn more about MD5? Is there any online tutorials? Thanks!
0
 
LVL 86

Expert Comment

by:CEHJ
ID: 11803745
See

http://javaalmanac.com/egs/java.security/Digest.html

You can write the byte buffer into the file
0
 
LVL 86

Accepted Solution

by:
CEHJ earned 50 total points
ID: 11803768
You can play with this: put it in a main method:

            String enteredPassword = args[0];
            java.security.MessageDigest md5 = java.security.MessageDigest.getInstance("MD5");
            // Just an example - all you'd be storing is 'digestedPassword' in a file
            String password = "abracadabra";
            byte[] digestedPassword = md5.digest(password.getBytes("UTF8"));
            byte[] enteredPasswordDigested = md5.digest(enteredPassword.getBytes("UTF8"));
            System.out.println(new sun.misc.HexDumpEncoder().encode(digestedPassword));
            System.out.println(new sun.misc.HexDumpEncoder().encode(enteredPasswordDigested));
            System.out.println(md5.isEqual(enteredPasswordDigested, digestedPassword)? "You're in!" : "No dice!");
0
 
LVL 86

Expert Comment

by:CEHJ
ID: 11804151
8-)
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
array220 challenge 8 48
XML Paring  Error - Premature end of file. 7 56
pairs challenge 5 45
micro services vs rest web services 16 53
For beginner Java programmers or at least those new to the Eclipse IDE, the following tutorial will show some (four) ways in which you can import your Java projects to your Eclipse workbench. Introduction While learning Java can be done with…
Introduction This article is the second of three articles that explain why and how the Experts Exchange QA Team does test automation for our web site. This article covers the basic installation and configuration of the test automation tools used by…
Viewers will learn about the regular for loop in Java and how to use it. Definition: Break the for loop down into 3 parts: Syntax when using for loops: Example using a for loop:
This video teaches viewers about errors in exception handling.

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now