|
|
Posted by Michael Fesser on 11/14/07 17:55
..oO(ZeldorBlat)
>If you're really concerned about security, I would store the passwords
>as a hash, transmit the actual password when logging in, and use SSL
>so the whole thing is encrypted.
To further improve the security the passwords should be stored as salted
hashes. Without a salt the same password will lead to the same hash,
which should be avoided.
Micha
Navigation:
[Reply to this message]
|