Article Preview
Buy Now
FEATURE
Locked Down—Part 1
A plain-English guide to encryption concepts and the Xojo/MBS toolkit
Issue: 24.4 (July/August 2026)
Author: William O'Keefe
Author Bio: William has 40+ years of experience in regulated medical environments. He brings that background to Xojo development with a focus on practical encryption techniques that meet real compliance requirements. He is the developer of LDSecureKit, a Xojo encryption module built on the MBS plugin suite.
Article Description: No description available.
Article Length (in bytes): 20,328
Starting Page Number: 34
Article Number: 24405
Related Link(s): None
Excerpt of article text...
It's 2:00 a.m. on a Tuesday, and your phone won't stop buzzing.
The messages are all variations of the same thing: something is wrong with the app. By the time you're fully awake and logged in, you already know what you're going to find. The database is intact. The server is fine. The code hasn't changed. But somewhere between your application and the outside world, 40,000 patient records—names, dates of birth, medication histories—made a trip they were never supposed to make. Unencrypted. Readable by anyone who grabbed them.
You encrypted the passwords. You were sure of that. What you didn't encrypt, because it seemed like overkill at the time, was everything else.
This scenario plays out in medical offices, legal firms, financial institutions, and small developer shops every year—often not at 2:00 a.m., often not discovered for months. The painful irony is that most of these breaches aren't the result of a sophisticated attack that cracked military-grade cryptography. They are the result of data that simply wasn't encrypted at all, or was encrypted in a way that amounted to the same thing: a Caesar cipher wearing a lab coat (see sidebar: The Caesar Cipher).
Consider what happened to Change Healthcare in February 2024. Attackers gained access to the largest healthcare payment clearinghouse in the United States, ultimately exposing records belonging to over 190 million patients. Before the incident was over, $22 million in ransom had been paid—without recovery of the stolen data. The total financial impact to UnitedHealth Group approached $3 billion. The root cause? A lack of multi-factor authentication on a critical remote-access Citrix portal, which allowed attackers using compromised credentials to walk in and move laterally through the entire system.
Read that again: compromised credentials and a missing layer of cryptographic protection. Not a nation-state exploit. Not a zero-day vulnerability. The two most common failures in breach post-mortems, hiding in plain sight.
...End of Excerpt. Please purchase the magazine to read the full article.










