in reply to Re: Protecting passwords in source
in thread Protecting passwords in source
"If you encrypted the password, you'd presumably then have to have a password to decrypt it and you're right back where you started from.
Not neccessary. An alternative, actually much better, is to compare the crypted password, not to decrypt it. Decrypt could even be impossible. (You got two instances of crypted passwords to compare: 1) at the time when the password is created, you crypt it and store it in the system; 2) when someone try to login or whatever, he/she provides the password, you crypt it in the same way as in step 1, and compare the crypted version with what is stored in the system.)
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: Protecting passwords in source
by jhourcle (Prior) on Jul 20, 2005 at 05:21 UTC | |
|
Re^3: Protecting passwords in source
by Fletch (Bishop) on Jul 20, 2005 at 13:25 UTC |