add backend encryption for all sensitive data
we should not save password (hashes), PINs etc. in plaintext.
Updated by The 2nd about 8 years ago
- Status changed from Neu to In Bearbeitung
- % Done changed from 0 to 90
current implementation uses AES encryption in CFB mode.
from Crypto.Cipher import AES
from Crypto import Random
def encrypt(aeskey, data):
""" encrypt string with given aes key """
iv = Random.new().read(AES.block_size)
cipher = AES.new(aeskey.decode("hex"), AES.MODE_CFB, iv)
encrypted_data = iv + cipher.encrypt(data)
still needs some investigation if this is the way to go. but replacing the encrypt/decryption functions should be easy.