tirana
Let’s say, there’s a server I have access to and which belongs to a customer. I’ve set up and launched a Phoenix app on it.
Because of our agreement with a customer, I’m not obliged to provide the source code of an app. The only thing I have to do is to lauch it end ensure that it works. Besides, I have a reason to try to protect the source code.
Question: how could I a) protect, or b) make it more difficult to get access to
the source code of said application?
More concretely:
1.1) Is there a way to distribute an app in the compiled form only?
I know how to build a release manually, and I’ve done it. However, there’re so many files there in it, and I don’t know which ones are essential for an app to run, and which aren’t.
1.2) Is there a way to also obfuscate the source code? Whether it be before, during or after compilation.
I’m aware that the maximum I could do is to make it more difficult to access the source code, or understand it. rather than protect it completely. And this is fine.
P.S. My local OS-es and the one on a server are identical. Therefore, I can compile a release locally. And I can set up all the env. locally as well.
Trending in Questions
Other Trending Topics
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixirconf-us
- #ai
- #blog-post
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #api
- #forms
- #metaprogramming
- #hex
- #security











Showing Posts 1 to 10- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
cmo
There are tools to decompile the beam files. There are several threads around asking this same question which you might want to check out. Short answer is: no.
Could you restrict access to the location of the files somehow?
tirana
That’s fine because a compiled version only on customer’s server will always be better than source code anyway. A customer may not be that tech-savvy to decompile it.
So – is it possible to have a compiled version only on a server to run an app?
How? A server belongs to a customer.
cmo
I thought you might be managing it for them.
tirana
In some cases I could, but I wouldn’t rely on it.
al2o3cr
Technical solutions can only put minor obstacles in the way. The correct tool for this is called “contract law”, and it doesn’t involve any software changes.
If you’re still interested in putting the obstacles in, it would be useful to think through exactly what you’re aiming to prevent. For instance, just writing really poorly-structured code with confusing function names would prevent anybody from understanding but that probably isn’t what you want
LostKobrakai
When you build a release (e.g. using
mix release) it won’t include source-code.Kurisu
If I understand you correctly you don’t want a perfect solution, but just something that makes your source code opaque to someone with no technical background.
Maybe the following project will interrest you then.
https://github.com/spawnfest/bakeware/
cmo
Using Burrito could be an obstacle. It will appear as an executable that will self extract. Bakeware has been superceded by Burrito, in a sense
Kurisu
Thank you for sharing.
Burrrito seems also to be more actively maintained.
https://github.com/burrito-elixir/burrito
tirana
Alright. now it’s become clear