Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6124593
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 23, 20262026-05-23T16:09:02+00:00 2026-05-23T16:09:02+00:00

I’m writing a program that, using Rijndael, will encrypt and decrypt files/folders using a

  • 0

I’m writing a program that, using Rijndael, will encrypt and decrypt files/folders using a user chosen password. Currently, when the user wants to encrypt something, they have to enter a password, that password is used to encrypt and when the user is ready to, decrypt the file/folder.

However, I would like to have a “master password” that will allow the user to only enter the password once in a “preferences” portion of the program, and then the program will automatically use that password for all encryption/decryption. This way they don’t have to put in a password every time they want to encrypt/decrypt.

Now, since programs like this are prone to many different kinds of attacks, how do I safely store the user’s “master password” so someone couldn’t get a hold of it? Storing it in the program in plain text is obviously not a good idea, so I could encrypt/decrypt the password with another password, chosen by me, and stored in the program.

However, again, if someone gets access to the password chosen by me to encrypt/decrypt the master password, then they could decrypt the master password and again, that wouldn’t be good.

SO! How do programs safely do this?

Currently I’m saving the “master password” by encrypting it using my own, chosen password, and storing it in a User-scoped setting. If you think this isn’t a good idea, please tell me why and what would you change about the process I currently have implemented?

Thank you!

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-23T16:09:03+00:00Added an answer on May 23, 2026 at 4:09 pm

    Do you know why websites won’t tell you your password when you lost it and they ask for a new one?
    Because they don’t know it. Yes, they don’t know it. They hash it and hash it good so they can only check your input password’s hash against the one in the database.

    Why all that?
    Because they cannot store it safely.
    They cannot encrypt it safely.

    This is a similar case.
    The best way is not to use a master password.

    When you encrypt a file, ask for a password and encrypt with the hash of the password.
    When decrypting, do ask for a password and attempt to decrypt.
    If it fails then it’s wrong.
    If it’s okay then it’s the right one.

    You can add some (shorter) dummy data before the file’s contents that you can use to check the key.


    If you try to use that to store the master password, you will enter an infinite loop of security, which is not a good idea.
    You’ll encrypt the password, and then encrypt the key used and then encrypt the key used to encrypt the first key etc.

    Edit: I am sorry about the discouraging nature of this answer but what you need to do is truly impossible.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

That's pretty much it. I'm using Nokogiri to scrape a web page what has
I'm parsing an RSS feed that has an ’ in it. SimpleXML turns this
link Im having trouble converting the html entites into html characters, (&# 8217;) i
I have a French site that I want to parse, but am running into
I have a bunch of posts stored in text files formatted in yaml/textile (from
We're building an app, our first using Rails 3, and we're having to build
I'm making a simple page using Google Maps API 3. My first. One marker
I need to clean up various Word 'smart' characters in user input, including but
We are using XSLT to translate a RIXML file to XML. Our RIXML contains
public static bool CheckLogin(string Username, string Password, bool AutoLogin) { bool LoginSuccessful; // Trim

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.