# The sqlcipher key security!

**URL:** <https://discuss.zetetic.net/t/the-sqlcipher-key-security/4633>\
**Category:** Uncategorized\
**Created:** [October 17, 2020, 1:13pm UTC](https://discuss.zetetic.net/t/the-sqlcipher-key-security/4633 "2020-10-17T13:13:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ellipse](https://avatars.discourse-cdn.com/v4/letter/e/e47774/32.png) [@ellipse](https://discuss.zetetic.net/u/ellipse)\
**Post date:** [October 17, 2020, 1:13pm UTC](https://discuss.zetetic.net/t/the-sqlcipher-key-security/4633/1 "2020-10-17T13:13:43Z")

</div>

SQLcipher implements the Function API（sqlite3\_key）that left by the SQLite3, and user can exectue "pragma key = ‘passphrase’ in the shell or ```use  
int sqlite3\_key(sqlite3 \*db, const void \*pKey, int nKey) to encrypted the whole database. It is very friendly to user, but where to store the key and how to protect the key ? If the key is leaked, the whole database is exposed to the attackers.

---

<div class="post-metadata">

**Author:** ![developernotes](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.zetetic.net/developernotes/32/1309_2.png) [@developernotes](https://discuss.zetetic.net/u/developernotes)\
**Post date:** [October 19, 2020, 12:15pm UTC](https://discuss.zetetic.net/t/the-sqlcipher-key-security/4633/2 "2020-10-19T12:15:24Z")

</div>

Hi @ellipse

Thanks for your interest in SQLCipher. We do offer some general guidance on key selection and management [here](https://discuss.zetetic.net/t/sqlcipher-database-key-material-and-selection/25), however, the level of security necessary for your application may vary from others. Without knowing the specifics, it is difficult to give concrete recommendations. That said, we strongly advise against including the key within the application source/binary itself.
