Skip to main content

Is there a way to block a class from being reflected upon?



I am making a cipher class while teaching myself about java's security api. This class is going to have some sensitive stuff in it, such as the type of encryption and the like. All of this can be reflectively retrieved it some one had the motivation.





I have used reflection to bypass private variables and methods before (not proud of it), so I know that can be done. Is there a way to wholly prevent reflection from working on an entire class - or even parts of it, or does that go against java's - more specifically the security api - design?


Comments

  1. This is called security by obscurity - if the details of your encryption algorithm being known would render it insecure, it already is insecure.

    No, you cannot stop people from reflecting on your class. In the very worst case, they could load a JNI library which would go straight into the JVM heap and read the memory contents from there (or write them)! If your code is running on a machine under the control of others, nothing it does is ever truly private.

    If you yourself write a JNI library, it can be decompiled and reverse engineered (and this is explicitly legal by past caselaw in many jurisdictions, moreover).

    Just make the algorithm secure even when its workings are known to all, or (better yet!) use an implementation which has already been written and is part of the Java language.

    If what you're worried about is the disclosure of keying material, use the Java methods for keystore access. If you're truly paranoid, enforce that the backing store be a PKCS11 hardware token.

    ReplyDelete
  2. No - if you don't have any control of the security managers involved, or of the physical distribution of your code, then anyone can have a look at it. Even if you can make sure that your app normally runs with a security manager which is configured to prevent reflection, if an attack has your code (e.g. a jar file) then they can run it however they like - or decompile it, look at the contents etc.

    ReplyDelete

Post a Comment

Popular posts from this blog

Why is this Javascript much *slower* than its jQuery equivalent?

I have a HTML list of about 500 items and a "filter" box above it. I started by using jQuery to filter the list when I typed a letter (timing code added later): $('#filter').keyup( function() { var jqStart = (new Date).getTime(); var search = $(this).val().toLowerCase(); var $list = $('ul.ablist > li'); $list.each( function() { if ( $(this).text().toLowerCase().indexOf(search) === -1 ) $(this).hide(); else $(this).show(); } ); console.log('Time: ' + ((new Date).getTime() - jqStart)); } ); However, there was a couple of seconds delay after typing each letter (particularly the first letter). So I thought it may be slightly quicker if I used plain Javascript (I read recently that jQuery's each function is particularly slow). Here's my JS equivalent: document.getElementById('filter').addEventListener( 'keyup', function () { var jsStart = (new Date).getTime()...

Is it possible to have IF statement in an Echo statement in PHP

Thanks in advance. I did look at the other questions/answers that were similar and didn't find exactly what I was looking for. I'm trying to do this, am I on the right path? echo " <div id='tabs-".$match."'> <textarea id='".$match."' name='".$match."'>". if ($COLUMN_NAME === $match) { echo $FIELD_WITH_COLUMN_NAME; } else { } ."</textarea> <script type='text/javascript'> CKEDITOR.replace( '".$match."' ); </script> </div>"; I am getting the following error message in the browser: Parse error: syntax error, unexpected T_IF Please let me know if this is the right way to go about nesting an IF statement inside an echo. Thank you.