Skip to Content
New release 12 available 🎉
ObfuscatorString Encryption

String Encryption

Babel Obfuscator provides the ability to encrypt code-inline strings using integrated string encryption algorithms. In addition to these built-in encryption algorithms, Babel also allows for custom string algorithms to be implemented through external code or plugins. This enables users to create their own unique encryption methods tailored to their specific needs.

Configuring String Encryption

Configuring string encryption with Babel Obfuscator involves selecting an encryption algorithm and setting it up for your application. Babel supports the XOR, HASH and STREAM algorithms out of the box. You can select any of the three in Babel Desktop, with command line flags or in your MSBuild project file. If none of them fits, you can implement Custom string encryption methods.

Whether opting for built-in algorithms or custom implementations, configuring string encryption enhances the security of your application by protecting sensitive strings from straightforward interception or manipulation.

Deploying on FIPS-enabled hosts? The XOR and HASH algorithms decrypt strings at runtime through the platform crypto provider, so a container running on a FIPS-enabled host without a certified OpenSSL FIPS provider can fail to start. See FIPS Compliance for the cause and the fix. The STREAM algorithm is not affected: its decryptor is fully managed and never calls the platform crypto provider.

Encryption Of Const Strings

A limitation within Babel Obfuscator is its inability to encrypt constant (const) strings because they are compiled into the application’s metadata, making them directly accessible by the CLR at runtime. To enable encryption for these strings, they must be converted to static readonly (for C#) or Shared ReadOnly (for VB.NET) fields. This approach allows Babel Obfuscator to process and encrypt such strings, thereby enhancing the security of your application by safeguarding sensitive information that would otherwise be exposed in plain text.

// Strings declared const cannot be encrypted public const string Connection = "Server=myServerAddress;Database=myDB;..."; // To encrypt, convert the above declaration to static readonly public static readonly string Connection = "Server=myServerAddress;Database=myDB;...";

Babel Desktop

In Babel Desktop, select the assembly on the project canvas and choose the algorithm (xor, hash, stream or custom) for StringEncryption in the Code encryption group of the properties panel. The list offers only the algorithms your license includes. For custom, the EncryptString and DecryptString methods must be defined in your code.

In This Section

  • Standard Algorithms — the built-in XOR, HASH and STREAM algorithms, how to enable each one, and a side-by-side comparison to help you choose.
  • Custom Algorithm — implement your own EncryptString / DecryptString methods to encrypt strings with an algorithm of your choice.
Last updated on