if stored clear in the database and transmitted in clear between the pc and the server its not a password its an invitaion to packet sniffers
hash: Md5 sha or otherwise (
md5 serverside |
md5 clientside) the password and verification of the password on the pc at account setup, and transmit & store the hash in the password column
hash the entry password on the pc and send the hash for verification
nobody knows what the password is, sniffers can't read the password
Users will continually make errors in this 4th char 3rd char crap
even if you ask for their name as a password people will count characters wrong
Last edited by almostbob; Sep 27th, 2009 at 3:35 pm.
Reputation Points: 562
Solved Threads: 368
Posting Maven
Offline 2,970 posts
since Jan 2009