No because you have to supply the key via an userinput and not hardcoded in the script...
if you put the key in the script you have lost, there is no way to "secure" it there. (only obscuring is possible)
Universal Extractor extract the nsi file
65 posts
and how can we work with that "obscuring" in nsis ?
Originally posted by arfghBe creative! Don't save you password as a simple plain string! Cut your password into several strings, add random characters to those strings and so on. Do everything that might confuse a person who is looking at the disassembly of your installer. At runtime you can calculate the correct password from the strings you have stored in your installer. And don't keep the result in memory any longer than you need it. But be aware that this will keep nobody away from reconstructing your password. It only makes things a tiny bit less trivial...
and how can we work with that "obscuring" in nsis ?
Very very simple example:
"Extract" that with Universal Extractor. You won't see the Password in plain text, but it's not too hard to guess the password 😁StrCpy $0 "M"
StrCpy $1 "O"
StrCpy $2 "W"
StrCpy $3 "R"
StrCpy $4 "S"
StrCpy $5 "Y"
StrCpy $6 "S"
StrCpy $7 "A"
StrCpy $8 "D"
StrCpy $9 "P"
MessageBox MB_OK "Super secret password: $0$5$9$7$6$4$2$1$3$8"
StrCpy $0 " "
StrCpy $1 " "
StrCpy $2 " "
StrCpy $3 " "
StrCpy $4 " "
StrCpy $5 " "
StrCpy $6 " "
StrCpy $7 " "
StrCpy $8 " "
StrCpy $9 " "
final conclusion. All this fact ruins the so good that the nsis is. At least for me !
Then why not leave NSIS behind, stop bothering the people they try to help you and use some Installer that provides better protection (in your imagination). And better hope the 7-Zip developers won't implement "support" for other Installers 😛