wow - ok - I'm on the same page as you now. Very clever ... so the only time your ever really exposed is during that brief period of de-compression, and then again, the password is never really exposed in the script anyways (its a $var) ... wow ...