I have an encrypted 7z file which has some binary data files.
- I am on windows platform (Windows 10 - Customers are also on same platform).
- I am using C++ 17.
- I am using a third party library (C standard) that can load these binary files only from disk (not from memory streams) into memory.
- Loading the bin files from disk to memory takes a few milliseconds.
- I don't want to let the users of my software to be able to read the content of the binary files.
- I can't use a online service to host these bin files because the customers should be able to use the software on a standalone computer without any network connectivity.
The way I am planning it now is as follows:
- Choose a random folder path at runtime (in the windows temp folder)
- Extract the encrypted 7z file to the above random path.
- Immediately acquire a exclusive lock on the bin files using https://docs.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-lockfileex
- Read the bin files
- After the reading is done, overwrite the files with zeros
- Delete the extracted files
Things that can go wrong in the above approach:
- Customers having admin privileges can potentially perfectly time the bin file loading in software and kill the process before the files are overwritten.
- Customers can potentially get a memory dump and read the data directly (not sure if this is so easy to pull off)
- Potentially more ways..
Is there any better way to deal with the situation? Should I live with the potential of IP loss.