Re: [WebDNA] Best practice re: password storage
This WebDNA talk-list message is from 2013
It keeps the original formatting.
numero = 110775
interpreted = N
texte = --089e01536b6a310f7b04e7c82f8aContent-Type: text/plain; charset=UTF-8Stuart,> [URL][URL][ENCRYPT seed=secret]password-value[/ENCRYPT][/URL][/URL]Hi - that's what I have been using as well. The problem is that if thesite is hacked the seed is accessible and all of the passwords areimmediately exposed.One client in particular has been advised that passwords should only bestored after being salted and encrypted using a one-way hash. The hashshould not be MD5 or SHA1. Their concern is that while a hack would bebad enough to deal with, it would be worse if they ended up exposing all ofthe users passwords, or were seen not to have taken measures to protect thepasswords.I would like to continue to use [encrypt] but I can't figure out whatalgorithm is used if no seed is specified.- Tom--089e01536b6a310f7b04e7c82f8aContent-Type: text/html; charset=UTF-8Content-Transfer-Encoding: quoted-printable
Stuart,
> =C2=A0[URL][URL][ENCRYPT s=eed=3Dsecret]password-value[/ENCRYPT][/URL][/URL]
Hi - that's what I have been using as w=ell. =C2=A0 The problem is that if the site is hacked the seed is accessibl=e and all of the passwords are immediately exposed.
One client in particular has been advised that password=s should only be stored after being salted and encrypted using a one-way ha=sh. =C2=A0 The hash should not be MD5 or SHA1. =C2=A0 Their concern is that= while a hack would be bad enough to deal with, it would be worse if they e=nded up exposing all of the users passwords, or were seen not to have taken= measures to protect the passwords.
I would like to continue to use [encrypt] but I can'=;t figure out what algorithm is used if no seed is specified.
- Tom
--089e01536b6a310f7b04e7c82f8a--
Associated Messages, from the most recent to the oldest:
--089e01536b6a310f7b04e7c82f8aContent-Type: text/plain; charset=UTF-8Stuart,>
[url][url][ENCRYPT seed=secret]password-value[/ENCRYPT][/URL][/URL]Hi - that's what I have been using as well. The problem is that if thesite is hacked the seed is accessible and all of the passwords areimmediately exposed.One client in particular has been advised that passwords should only bestored after being salted and encrypted using a one-way hash. The hashshould not be MD5 or SHA1. Their concern is that while a hack would bebad enough to deal with, it would be worse if they ended up exposing all ofthe users passwords, or were seen not to have taken measures to protect thepasswords.I would like to continue to use
[encrypt] but I can't figure out whatalgorithm is used if no seed is specified.- Tom--089e01536b6a310f7b04e7c82f8aContent-Type: text/html; charset=UTF-8Content-Transfer-Encoding: quoted-printable
Stuart,
> =C2=A0
[url][url][ENCRYPT s=eed=3Dsecret]password-value[/ENCRYPT][/URL][/URL]
Hi - that's what I have been using as w=ell. =C2=A0 The problem is that if the site is hacked the seed is accessibl=e and all of the passwords are immediately exposed.
One client in particular has been advised that password=s should only be stored after being salted and encrypted using a one-way ha=sh. =C2=A0 The hash should not be MD5 or SHA1. =C2=A0 Their concern is that= while a hack would be bad enough to deal with, it would be worse if they e=nded up exposing all of the users passwords, or were seen not to have taken= measures to protect the passwords.
I would like to continue to use
[encrypt] but I can'=;t figure out what algorithm is used if no seed is specified.
- Tom
--089e01536b6a310f7b04e7c82f8a--
Tom Duke
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
too many nested tags ... (1997)
Auto entering Friday's date in a field (2002)
Country & Ship-to address & other fields ? (1997)
Browser Reloads and AddlineItem (1997)
[getchars] questions (1997)
Shipping Help! (1998)
Summary search -- speed (1997)
Reversed words (1997)
[NT] ie 4.0 required (1997)
creator code (1997)
Web Logs (1998)
REPLACE problem (2000)
Your personal 5.1 WebDNA Lab now available on the DRC (2003)
Greeting Card System (2000)
How to Sort Summ data ? (1997)
protect tag not working (1998)
Updating a database once per day - An example (1998)
Calendar (1997)
Two prices in shoppingcart? (1997)
XML WebDNA Problems (2000)