best way store sensitive data in files

  • (2 Pages)
  • +
  • 1
  • 2

17 Replies - 339 Views - Last Post: 29 May 2019 - 02:45 PM Rate Topic: -----

#1 testmetestyou   User is offline

  • D.I.C Head

Reputation: 0
  • View blog
  • Posts: 94
  • Joined: 19-July 16

best way store sensitive data in files

Posted 26 May 2019 - 08:28 AM

What is best way to store sensitive data what is encrypted?
I dont want use database.
I want use without database, but secure way or something.
Im using ParagonIE Halite for encryption and decryption.

Any snippets?
Is This A Good Question/Topic? 0
  • +

Replies To: best way store sensitive data in files

#2 modi123_1   User is online

  • Suitor #2
  • member icon



Reputation: 15077
  • View blog
  • Posts: 60,210
  • Joined: 12-June 08

Re: best way store sensitive data in files

Posted 26 May 2019 - 08:31 AM

What sort of sensitive information?

You could store the information outside of the root web directory so folks can't browse to it.

There's hashing and salting..
Was This Post Helpful? 0
  • +
  • -

#3 testmetestyou   User is offline

  • D.I.C Head

Reputation: 0
  • View blog
  • Posts: 94
  • Joined: 19-July 16

Re: best way store sensitive data in files

Posted 26 May 2019 - 08:32 AM

Sensitive data like usernames, passwords, product codes, product sensitive data.
Any good way to store them? json? array? so if decrypt file it is easy to get information from file..
Was This Post Helpful? 0
  • +
  • -

#4 modi123_1   User is online

  • Suitor #2
  • member icon



Reputation: 15077
  • View blog
  • Posts: 60,210
  • Joined: 12-June 08

Re: best way store sensitive data in files

Posted 26 May 2019 - 08:34 AM

Product codes? Ooookay.. let's take a knee for a minute. Why wouldn't that be stored in a DB?
Was This Post Helpful? 1
  • +
  • -

#5 testmetestyou   User is offline

  • D.I.C Head

Reputation: 0
  • View blog
  • Posts: 94
  • Joined: 19-July 16

Re: best way store sensitive data in files

Posted 26 May 2019 - 08:36 AM

Its factory which uses own webserver and if connection is lost then localhost still works fine.. I've thinked store in files is best way.
Was This Post Helpful? 0
  • +
  • -

#6 modi123_1   User is online

  • Suitor #2
  • member icon



Reputation: 15077
  • View blog
  • Posts: 60,210
  • Joined: 12-June 08

Re: best way store sensitive data in files

Posted 26 May 2019 - 08:54 AM

Let's follow this rabbit for a minute. Does this website need to be "installed" on each and every device instead of using a a browser to navigate to the page?
Was This Post Helpful? 0
  • +
  • -

#7 testmetestyou   User is offline

  • D.I.C Head

Reputation: 0
  • View blog
  • Posts: 94
  • Joined: 19-July 16

Re: best way store sensitive data in files

Posted 26 May 2019 - 08:59 AM

Webserver is in intranet, so no other outside hosting services..
Website installed in webserver and I've thinked using storing sensitive data inside files because if ethernet connection is lost then in factory you can still view website with local ip.
I dont think it would work with database.
Because if we have connection I can view website from external network if you understand me.
Was This Post Helpful? 0
  • +
  • -

#8 modi123_1   User is online

  • Suitor #2
  • member icon



Reputation: 15077
  • View blog
  • Posts: 60,210
  • Joined: 12-June 08

Re: best way store sensitive data in files

Posted 26 May 2019 - 09:02 AM

Intranet webservers still have routed domains to go to. It's common practice.

PHP requires a webserver to.. well.. serve up the files. There is no local files outside of the occasional cached in a browser and even then if someone attempts to navigate to where ever the files are stored they won't run.

Localhost development is not to be confused with thinking that's how random device will interact with it all.
Was This Post Helpful? 1
  • +
  • -

#9 testmetestyou   User is offline

  • D.I.C Head

Reputation: 0
  • View blog
  • Posts: 94
  • Joined: 19-July 16

Re: best way store sensitive data in files

Posted 26 May 2019 - 09:32 AM

If I use ip addresses and not using domains?
So I can use storing sensitive data in files but cant use Database because intranet ip address for database is different and same with external network database ip address.

Explaination:

Webserver intranet 192.168.1.10
Webserver external 88.43.23.120

Database intranet 192.168.1.11
Database external 88.43.23.121 //idk

If i want use database I must always change database credientals..
Like if use external network then must use external ip address but internet connection lost then must change back to local/intranet ip address.. //thats the problem

But if I dont have database then I dont have to worry for credientals. I cant view all the time in internal connection and external connection.
And if like worker workin in website and is with internal ip address then cutting network cable doesnt stop him with working it.

My problem was that workers must can always work in website scanning products..
When connection lost then it still possible to work on website, but if have connection so you can view site also around the world, like regular website.
Using own webserver and using storing data in files will work for this solution I think..
Was This Post Helpful? 0
  • +
  • -

#10 modi123_1   User is online

  • Suitor #2
  • member icon



Reputation: 15077
  • View blog
  • Posts: 60,210
  • Joined: 12-June 08

Re: best way store sensitive data in files

Posted 26 May 2019 - 09:55 AM

Subdomains can work only internally when folk are on the network. Like "internal.dreamincode.net". It's a common enterprise practice.

Again - if there is no webserver working then php in a browser won't be working either. Localhost development works because it has a faux webserver going. This will not be the case when you deploy the php pages.
Was This Post Helpful? 0
  • +
  • -

#11 testmetestyou   User is offline

  • D.I.C Head

Reputation: 0
  • View blog
  • Posts: 94
  • Joined: 19-July 16

Re: best way store sensitive data in files

Posted 26 May 2019 - 10:31 AM

webserver uses static ip so if internet connection lost you can still work offline in intranet?
Its hard to explain..

If i cut cable between "internet client"(internet provider?) and "firewall" so I can still work "offline mode" in intranet but not accessable from external network because "internet client" cable is cut off. But if it isn't you can access from static ip and from external network, so cutting off cable or losting connection cant affect working on static ip address intranet network.. huh.. Sorry I dont know if you understand my explaination.. English is my second language.

Image:
https://systemscenter.ru/smsv4.en/local/0bfb9b72-fcfb-421e-a8c1-61de1f7fa588.gif

This post has been edited by testmetestyou: 26 May 2019 - 10:34 AM

Was This Post Helpful? 0
  • +
  • -

#12 CTphpnwb   User is offline

  • D.I.C Lover
  • member icon

Reputation: 3817
  • View blog
  • Posts: 13,889
  • Joined: 08-August 08

Re: best way store sensitive data in files

Posted 26 May 2019 - 12:26 PM

Do you know that the database server is not required to be running on different hardware? So, if you can get to the web server and run the php script, why can't you get to the same server and access the database?
Was This Post Helpful? 0
  • +
  • -

#13 testmetestyou   User is offline

  • D.I.C Head

Reputation: 0
  • View blog
  • Posts: 94
  • Joined: 19-July 16

Re: best way store sensitive data in files

Posted 26 May 2019 - 03:12 PM

Yes I know but database also use different static address, I'm right?
I cant use external IP IPv4 address ex. 88.34.23.120 in offline mode if provider is doing maintenance work on internet.
Then I must have like 2 configs for database external and internal network with database IP address (host).
Or anyone know better how people in factorys can do their job without ethernet in internal network with their own web server and using own website where putting data?
My guess for working solution is store sensitive data in files or something there must be great solution for that.
So if I scan all the day product codes to website and ethernet connection lost by provider then I must still have to work on website. Solution is static IP address for webserver on OUR internal network. You can only access to website when ethernet provider ethernet is connected then you can access from external network so you can scan product codes outside factory.
You know factorys have poor ethernet connections so I cant use hosting providers for holding my website and data, so build one and hold my website there and in internal network I can work 24/7 with ethernet and without ethernet connection.
So if workers using static local IP 192.168.0.10 then they doesnt need worry if ethernet connection is lost or not. (Internal static is for workers to insert data)
And also from external ip address 88.34.23.120 I can access when there is connection in factory webserver and can access anywhere. (External is more like for viewing data and how workers go)

Huh its hard to explain...
Was This Post Helpful? 0
  • +
  • -

#14 CTphpnwb   User is offline

  • D.I.C Lover
  • member icon

Reputation: 3817
  • View blog
  • Posts: 13,889
  • Joined: 08-August 08

Re: best way store sensitive data in files

Posted 26 May 2019 - 04:40 PM

You did not answer my question: If you can run php using an IP address, why can you not get to mysql on the same server using the same ip address?
Was This Post Helpful? 0
  • +
  • -

#15 testmetestyou   User is offline

  • D.I.C Head

Reputation: 0
  • View blog
  • Posts: 94
  • Joined: 19-July 16

Re: best way store sensitive data in files

Posted 27 May 2019 - 03:20 AM

But in database config you must change the IP(Host) address? if Im in internal network then it uses internal host ip address (Yes it can be same with webserver). But if im external network it must use external host ip address? or in both mode it can use as "localhost"?
Was This Post Helpful? 0
  • +
  • -

  • (2 Pages)
  • +
  • 1
  • 2