Disclaimer

Any opinions expressed here are my own and not necessarily those of my employer (I'm self-employed).

Nov 2, 2011

Base64 decode online — are you sure?

Are you using one of the many web pages that let you base64 decode data? In that case you should take a moment to think about the nature of the data you want to decode and what those pages could be doing with the data — apart from showing you the decoded version.
tl;dr: Check out transformtool.codeplex.com for an offline alternative to the online Base64 decoders.
Google's keyword tool reports 9,900 monthly searches for "base64 decode online". How many of these searches lead to disclosure of sensitive business information, or personal information (PII) to one of the Base64 decoding webpages? None of these searches are from IT-professionals trying to figure out what's wrong in a production system, right?

Top Google results for "base64 decode online" at time of writing


Doing a quick review of the top ten results of a Google search for base64 decode online I found that none of the online base64 decoders offered secure communications to the server by default (i.e. no HTTPS). That means that whatever data you're sending over the wire is not protected by end-to-end encryption, so you cannot guarantee the confidentiality while it's in transit. Note also that it's no longer Base64 encoded when you get the response back, then it's human readable and can be easily recognized as sensitive information.

The Base64 decoding websites contain no information on whether they might use the data for any purpose, or if the data you send to them is stored in any way on the server(s). So you have no guarantees for the information's confidentiality on the server either. Unless you check specifically (every time!), you have no idea where the sites' web servers are located. In effect you might be shipping company data out of the country. Explain that to the compliance department...

What should you do?
You should install an application locally that lets you decode the data. Web application security proxies such as Burp and Fiddler support Base64 encoding/decoding, and they're also great debugging tools for web applications. However, they might need administrator rights to install properly.

TransformTool is an encoding/decoding tool that supports Base64 (disclaimer: I wrote it). It installs locally and runs with restricted privileges. The installation is simple, and does not require administrator privileges on the computer.

So, find a trustworthy tool that installs locally on your computer. Use that for your Base64 decoding needs instead of sharing the data on the Internet!

34 comments:

  1. I don't know about Fiddler, but Burp Suite definitely does not require administrator rights to install (it's more or less just a .jar file that you run).

    ReplyDelete
  2. Ok, thanks! As you can see from my previous post, I've uninstalled Java. So I wouldn't know. :)

    ReplyDelete
  3. Most Linux distributions comes preinstalled with the "base64" commandline tool. It's even part of the Linux in your browser distribution at http://bellard.org/jslinux/. This means you can do fun things like pasting "c2VjcmV0Cg==" into the clipboard and issuing the command "base64 -d /dev/clipboard".

    Since it runs entirely within a temporary virtual machine executing locally, no content sent anywhere or is stored anywhere. If you're not willing to trust that Bellard hasn't added any malicious code to the JSLinux you can disable the network after loading up the page.

    ReplyDelete
  4. Cool! Hadn't seen that one. I'm not sure disabling the network would be a viable option, wouldn't that break the Facebook updates? :)

    I guess Cygwin includes the base64 command line tool too, which would be useful for working with (large) files on a Windoze installation.

    Running Linux in the browser made me, well, miss Linux... Thanks a lot.

    ReplyDelete
  5. FYI: There is one online Base64 decoder that does offer secure SSL secure transfer and a decent privacy policy. Check out this one:

    Secure Base64 Decoder

    ReplyDelete
    Replies
    1. Hi, thanks for the tip!

      Still, I'll have to stick with my recommendation of finding a tool that can do this locally for you. If you're working with PII or other sensitive data it's not a great idea to post it to some site abroad. :)

      Delete
  6. Wanna know more about cell phone lookup by name? Read information here.

    ReplyDelete
  7. LOOKING FOR SOMEONE WRITE All ASSIGNMENT HELP
    For getting the best essays written hire the Professional Essay Writers of all assignment help.com who have knowledge in every field to write the best essays for you.Expert assignment helpers of All Assignment Help are well efficient and capable of creating unique assignments for college or university students all across the globe.

    ReplyDelete
  8. Students Assignment Help offers the best MBA assignment help services to the students. We have 3000+ expert writers in the industry and they provide the excellent quality assignment writing services to the students from.

    ReplyDelete
  9. A brilliant anecdote about a physicist who dumps significant into the puzzle of dimensional measurements that may underlie probably the most imperative militaries in nature

    ReplyDelete
  10. Very informative written post. The writer here has done a great job. I personally use them exclusively high-quality elements. I would love to see more of the same from you. Thank you for discussing this great post. the article is very useful for me .. thank you for sharing this article.

    law assignment writing services
    Civil Engineering Assignment Help
    Nursing assignment writing services
    Accounting assignment writing services

    ReplyDelete
  11. Students while completing their assignments might be required to avail Nursing Assignment Help, SWOT Analysis Help, Market Conditions Homework help, and comment on or Design New Product Assignment help. Alternately, students might not just only want online assignment help but might also want economics teaching help so as to better understand the subject. while seeking Biology assignment help online might be necessary to keep up with the course load, developing personal expertise and knowledge in project management assignments is also vital.

    ReplyDelete
  12. This comment has been removed by the author.

    ReplyDelete
  13. Meets, Play layers, Polo shirts, Business venture a an informal and consequently pants(Which is geared up meet in order over"Leg protection") Allow you design a (Michael Kors Outlet Store) couple work (Michael Kors Outlet) garments that do (New Jordan Releases 2020) not always make you imitating your mother(Truth in the event that father's a muted colors caring individual, He previously constitute exact on your property web page). (Cheap Yeezy Shoes Sale) Could you ought not risk utilized a darn wrap, Although think about (Coach Outlet Clearance Sale) this excellent: Would definitely probably transfer in with pops?Walking foot throughout a store is introduced to (Ray Ban Outlet Store) work enviroment is quickly stress-free. This item reduces which usually hurt in your mind, Of which compact metro in the (Yeezy Boost 350 Cheap) spine dreads everything is previously been ended.

    My husband teaches (Coach Outlet Store Online) everything, Physical abides in staff members main a place to live, Consumes at the park and may possibly divided everything ranging taken

    ReplyDelete
  14. Building Information Modeling (BIM) is an intelligent 3D model-based process that gives architecture, engineering, and construction (AEC) professionals the insight and tools to more efficiently plan, design, construct, and manage buildings and infrastructure.

    ReplyDelete
  15. I am very glad to visit on this blog because I have succeeded to find a lot of information for my writing strategies which I can use for online writing help.
    dissertation proposal writing services

    ReplyDelete
  16. Thank you! Finally I've found the tutorials you need on hotmail login which will be really helpful for anyone who can't sign in email address, sign up new email, or want to try other useful tools.

    ReplyDelete
  17. AtozTopNews is another well-known and well-known technology blog for geeks primarily interested in reading technology reports, reviews of products, details about products, etc. It also provides exciting tutorials on technology and how it impacts society. AtoztopNews is another site for technology, computer gaming equipment, and fascinating lifestyle guides. It also offers information on music, automobiles, photography, and cars and occasionally writes about Apple news, too.

    ReplyDelete
  18. Halftime VST Crack
    Mac transforms every audio into a dark down-tempo version of itself and gives your songs an enormous atmosphere and feel. Lead synthesizers turn into heavy bass EDM monsters. The plinky piano lines become melodies of haunting traps. The drums get thicker and wider to reveal new rhythmic possibilities.

    ReplyDelete
  19. "이용이유가생기는곳 먹튀검증 안전노리터 go"

    ReplyDelete
  20. The online Base64 decoder does offer secure SSL secure transfer and a decent privacy policy. Now its time to availshop fittersfor more details.

    ReplyDelete
  21. No matter, it is a transformative enterprise solution or a consumer oriented app, OSL leads to the complete app development process from ideation to concept delivery and to long term consistent support

    ReplyDelete
  22. I am very happy to see your article after a long time. Its a nice informative article. Now its time to avail limo service bay area for more information.

    ReplyDelete
  23. This online base64 decoder seems promising! I was skeptical at first, but it turned out to be reliable and efficient. Now I can easily decode my base64 strings without any hassle. Great job! By the way, if you know any trustworthy platforms that can do my assignment please let me know. Thanks!

    ReplyDelete
  24. For expat car owners looking to sell their Toyota cars, there are various options available to simplify the process. Selling your Toyota involves finding trusted platforms or dealers specializing in buying pre-owned vehicles. By leveraging these resources, expat car owners can ensure a fair valuation based on the car's condition and market demand. These platforms and dealers provide a convenient and reliable avenue to connect with potential buyers, increasing the chances of a successful sale. With the right approach, expat car owners can confidently sell their Toyota cars and achieve a satisfactory outcome.

    ReplyDelete
  25. Discover Innovation at its Finest with Hube Limited Pakistan! 🔥 Explore a world of possibilities with our exceptional range of Hube products. From cutting-edge gadgets to must-have accessories, we bring you the latest in technology and convenience. Elevate your lifestyle with our thoughtfully designed solutions that seamlessly integrate into your everyday. Experience innovation like never before, only at Hube Limited Pakistan. 💼🔌 #HubeProducts #InnovationUnleashed

    ReplyDelete

  26. Exosomes therapy is a new and emerging treatment that uses extracellular vesicles (EVs) to deliver therapeutic cargo to cells. EVs are small, membrane-bound particles that are released by cells into the extracellular botox. They are thought to play a role in cell-to-cell communication and have been shown to carry a variety of proteins, nucleic acids, and other molecules.

    ReplyDelete
  27. I'm not sure if it's safe to base64-decode something online. There's always the possibility that the code could be malicious and could harm your computer. If you're really sure you want to do it, I would recommend using a reputable online decoder that has good security exosomes facial in place. One thing to keep in mind is that base64 is often used to encode sensitive data, such as passwords and credit card numbers. If you're decoding something that contains this type of data, it's important to be extra careful.

    ReplyDelete

Copyright notice

© André N. Klingsheim and www.dotnetnoob.com, 2009-2018. Unauthorized use and/or duplication of this material without express and written permission from this blog’s author and/or owner is strictly prohibited. Excerpts and links may be used, provided that full and clear credit is given to André N. Klingsheim and www.dotnetnoob.com with appropriate and specific direction to the original content.

Read other popular posts