Re: [WebDNA] Best practice re: password storage

This WebDNA talk-list message is from

2013


It keeps the original formatting.
numero = 110783
interpreted = N
texte = This is a multi-part message in MIME format. ------=_SW_161490865_1380751577_mpa= Content-Type: text/plain; charset=utf-8; format=flowed Hi Tom, no time right now... but my .02¢ below: > can anyone tell me what algorithm is used? You could probably find this out... but it's against WSC's policy to talk about this publicly. > Also how are other people handing password storage? There is a school of thought that passwords should be a one-way only hash... which ideally, I agree. [encrypt] without a seed value does indeed produce the same value.. but there is also [encrypt method=apop].. which is MD5... you could also use [Shell] to access higher-bit hash techniques.. but basically, they'd all work. It's the random-per-password salting that counts the most I think. Donovan > --------------------------------------------------------- This message > is sent to you because you are subscribed to the mailing list > . To unsubscribe, E-mail to: > archives: > http://mail.webdna.us/list/talk@webdna.us Bug Reporting: > support@webdna.us ------=_SW_161490865_1380751577_mpa= Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable
 Hi Tom, no time right now... but my .02=c2=a2 below:

= > can anyone tell me what algorithm is used?


You could probabl= y find this out... but it's against WSC's policy to talk about this publicly= .


> Also how are other people handing p= assword storage?


There is a school of thought that passwords shou= ld be a one-way only hash... which ideally, I agree.
[encrypt] without a= seed value does indeed produce the same value.. but there is also [encrypt = method=3dapop].. which is MD5... you could also use [Shell] to access higher= -bit hash techniques.. but basically, they'd all work. 

It's th= e random-per-password salting that counts the most I think.

Donovan<= br>

    
--------------------------------------------------------- This message is= sent to you because you are subscribed to the mailing list <talk@webdna.= us>. To unsubscribe, E-mail to: <talk-leave@webdna.us>archives: http://= mail.webdna.us/list/talk@webdna.us Bug Reporting: support@webdna.us
------=_SW_161490865_1380751577_mpa=-- Associated Messages, from the most recent to the oldest:

    
  1. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  2. Re: [WebDNA] Best practice re: password storage (Tom Duke 2013)
  3. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  4. Re: [WebDNA] Best practice re: password storage (WebDNA 2013)
  5. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  6. Re: [WebDNA] Best practice re: password storage (WebDNA 2013)
  7. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  8. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  9. Re: [WebDNA] Best practice re: password storage (WebDNA 2013)
  10. Re: [WebDNA] Best practice re: password storage (Bill DeVaul 2013)
  11. Re: [WebDNA] Best practice re: password storage (Donovan Brooke 2013)
  12. Re: [WebDNA] Best practice re: password storage (Stuart Tremain 2013)
  13. Re: [WebDNA] Best practice re: password storage (Tom Duke 2013)
  14. Re: [WebDNA] Best practice re: password storage (Stuart Tremain 2013)
  15. Re: [WebDNA] Best practice re: password storage (Tom Duke 2013)
  16. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  17. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  18. Re: [WebDNA] Best practice re: password storage (Stuart Tremain 2013)
  19. Re: [WebDNA] Best practice re: password storage (Tom Duke 2013)
  20. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  21. Re: [WebDNA] Best practice re: password storage (Stuart Tremain 2013)
  22. [WebDNA] Best practice re: password storage (Tom Duke 2013)
This is a multi-part message in MIME format. ------=_SW_161490865_1380751577_mpa= Content-Type: text/plain; charset=utf-8; format=flowed Hi Tom, no time right now... but my .02¢ below: > can anyone tell me what algorithm is used? You could probably find this out... but it's against WSC's policy to talk about this publicly. > Also how are other people handing password storage? There is a school of thought that passwords should be a one-way only hash... which ideally, I agree. [encrypt] without a seed value does indeed produce the same value.. but there is also [encrypt method=apop].. which is MD5... you could also use [shell] to access higher-bit hash techniques.. but basically, they'd all work. It's the random-per-password salting that counts the most I think. Donovan > --------------------------------------------------------- This message > is sent to you because you are subscribed to the mailing list > . To unsubscribe, E-mail to: > archives: > http://mail.webdna.us/list/talk@webdna.us Bug Reporting: > support@webdna.us ------=_SW_161490865_1380751577_mpa= Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable
 Hi Tom, no time right now... but my .02=c2=a2 below:

= > can anyone tell me what algorithm is used?


You could probabl= y find this out... but it's against WSC's policy to talk about this publicly= .


> Also how are other people handing p= assword storage?


There is a school of thought that passwords shou= ld be a one-way only hash... which ideally, I agree.
[encrypt] without a= seed value does indeed produce the same value.. but there is also [encrypt = method=3dapop].. which is MD5... you could also use [shell] to access higher= -bit hash techniques.. but basically, they'd all work. 

It's th= e random-per-password salting that counts the most I think.

Donovan<= br>

    
--------------------------------------------------------- This message is= sent to you because you are subscribed to the mailing list <talk@webdna.= us>. To unsubscribe, E-mail to: <talk-leave@webdna.us>archives: http://= mail.webdna.us/list/talk@webdna.us Bug Reporting: support@webdna.us
------=_SW_161490865_1380751577_mpa=-- Donovan Brooke

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

list cookies and list http headers (1997) taxrate (1999) The beginning (1997) [WriteFile] problems (1997) Emailer setup (1997) WebCat2b13MacPlugIn - [include] (1997) Email encryption (1998) Sorting (2000) Date search - yes or no (1997) Open Market's Transact & Macintosh (1998) RE: Loss in form (1998) Calculate UnitShipCost in Formulas.db (1999) [append] vs. [appendfile] delta + question? (1997) Grep Search and Replace (2002) Big Databases (1997) WCS Newbie question (1997) Emailer port change (1997) Dynamic Exchange Rates (2002) shownext and searches (2002) WebCat2 - [include] tags (1997)