-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Luis, et al --

...and then Luis Lebron said...
% 
% Any suggestions of a "secure" way of storing membership passwords (for a
% website) in a mysql database? Should I use sha, aes, des???

Do you really need to be able to decrypt and get the plaintext password?
Why not instead save the encrypted password and then when checking always
encrypt what you're given and compare it?  Not only is it more secure,
it's easier :-)


% 
% thanks,

Sure thing.


% 
% Luis R. Lebron
% Sigmatech, Inc


HTH & HAND

:-D
- -- 
David T-G                      * There is too much animal courage in 
(play) [EMAIL PROTECTED] * society and not sufficient moral courage.
(work) [EMAIL PROTECTED]  -- Mary Baker Eddy, "Science and Health"
http://justpickone.org/davidtg/      Shpx gur Pbzzhavpngvbaf Qrprapl Npg!

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (FreeBSD)

iD8DBQE/rHlvGb7uCXufRwARApWPAKC+UEfw8KCw9nlEpEyr+CL4jye+aACfXUn7
wFFJqHnQRb3ejCoheF3mNuU=
=Gefq
-----END PGP SIGNATURE-----

-- 
MySQL General Mailing List
For list archives: http://lists.mysql.com/mysql
To unsubscribe:    http://lists.mysql.com/[EMAIL PROTECTED]

Reply via email to