Question

Is storing secret keys (internal use passwords and such) on iPhone source code and project resources (such as plist files) secure?

Obviously nothing is 100% secure, but can this information be extracted easily from an installed app?

How do you recommend storing these keys to use them in the source code?

Just in case, this question is not about storing user passwords.

Was it helpful?

Solution

Found basically the same question with a longer discussion:

How would you keep secret data secret in an iPhone application?

To sump up: it seems there's no official way to securely store secret keys in the app binary.

Sorry for posting a duplicate question.

OTHER TIPS

A lot depends on what you mean by secure. For normal device use it could be considered secure in that there is no way for a user to access it. However all bets are off for a jail-broken device which has complete access to the filesystem. So viewing a plist file in your application bundle is trivial on a jail-broken phone.

You might consider the use of the keychain which in theory would be safer and also has the advantage that the data will survive a reinstallation of your app. As before on a jail broken device nothing can be considered to be 100% secure but it depends how much trouble you want to go to.

Licensed under: CC-BY-SA with attribution
Not affiliated with StackOverflow
scroll top