Thread: Polarismail
View Single Post
Old 29 May 2012, 02:14 AM   #22
SethM
Senior Member
 
Join Date: Oct 2009
Location: Nevada
Posts: 142

Representative of:
Rollernet.us
Quote:
Originally Posted by kijinbear View Post
Thanks for the clarification. I'm thinking you could perhaps encrypt third-party credentials with the user's own password so that it is decrypted only when needed... But what you're doing is still leaps and bounds better than some other providers (ahem FM ahem) who didn't even encrypt their users' passwords the last time the topic came up in these forums. That should be good enough unless OP is really paranoid.
IMO that would be just as bad as storing the user's password in the clear. User passwords should be one-way hashed, never encrypted (which is reversible).

http://en.wikipedia.org/wiki/Cryptog..._hash_function

Last edited by SethM : 29 May 2012 at 02:15 AM. Reason: Wikipedia link on hashing
SethM is offline   Reply With Quote