I had no idea that SHA1 is better than MD5. I'll have to use that instead. It appears I don't get a donut as well :-) My original implementation was to store password cookies, but after learning about sessions and all of the other options that were much more secure than cookies... I don't know what I was thinking. Good to know about the Credit Cards and the SSL. Luckily I don't need that for this project, but I have always been curious about how to design transaction-secure applications. Thanks for your advice. Joe