in reply to Re^7: encrypt passwords
in thread encrypt passwords
In summary, even you are admitting that without compromise, your only recourse is to tell your boss 'no'.
If that's your summary, you didn't read what I wrote.
You don't tell your boss: "No!". You tell your boss: "There are things we could do, but there is no point in doing them." And then you explain why.
You have offered no alternative
I have. Fix the authentication mechanism. Properly.
To get into the detail of how to go about that would require much more than your vague description.
Yes, someone who speaks Perl (or any of a dozen other C-like languages) will probably be able to hack the passwords if they have access to the module. But that does add a layer of knowledge required.
Sorry, but protecting against those with no skills is like wearing a pinafore in a war zone.
And offering obfuscation as security is tantamount to fraud.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^9: encrypt passwords
by marinersk (Priest) on Apr 18, 2015 at 01:43 UTC | |
by BrowserUk (Patriarch) on Apr 18, 2015 at 07:45 UTC | |
by marinersk (Priest) on Apr 19, 2015 at 02:53 UTC | |
by Anonymous Monk on Apr 19, 2015 at 05:41 UTC | |
by AnomalousMonk (Archbishop) on Apr 18, 2015 at 04:09 UTC | |
by marinersk (Priest) on Apr 19, 2015 at 02:55 UTC |