douzhui8531 2019-02-01 17:34
浏览 42

最佳实践:如果用户上传文件,它会更安全吗?

right now, the userdata stored in my (MariaDB-)database is encrypted (AES). The data is encrypted whenever users post or edit the data; the 40+-digit encryption-key was created randomly with the user account and is then stored inside a file in an extra folder that is secured by a .htaccess-file. So even when the database is breeched, no cleartext data should be visible to the attacker - unless the attacker also gains control over the keyfile, which is stored on the same server.

My question is: would it be more secure if a user has to upload the keyfile for encryption everytime after login? The last filepath could be stored and used in the input-field, so that there is at least rudimentary comfort when doing this.

It would be like this: 1. User -> Login 2. If login confirmed: upload keyfile in a next step from the local computer to the server 3. Server -> confirm keyfile 4. The confirmed keyfile will be then encrypted by a temporary encryption key and stored inside the $_SESSION-variable, which will expire after 30 minutes of inactivity.

Of course this approach is not as comfortable as just login in, but I think it will be more secure in case of a security breach of the server (?).

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥100 为什么这个恒流源电路不能恒流?
    • ¥15 有偿求跨组件数据流路径图
    • ¥15 写一个方法checkPerson,入参实体类Person,出参布尔值
    • ¥15 我想咨询一下路面纹理三维点云数据处理的一些问题,上传的坐标文件里是怎么对无序点进行编号的,以及xy坐标在处理的时候是进行整体模型分片处理的吗
    • ¥15 CSAPPattacklab
    • ¥15 一直显示正在等待HID—ISP
    • ¥15 Python turtle 画图
    • ¥15 关于大棚监测的pcb板设计
    • ¥15 stm32开发clion时遇到的编译问题
    • ¥15 lna设计 源简并电感型共源放大器