Re: [WebDNA] Best practice re: password storage

This WebDNA talk-list message is from

2013


It keeps the original formatting.
numero = 110785
interpreted = N
texte = --Apple-Mail=_6B24514A-B49F-4FA4-B59D-DE17A0B70E11 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=iso-8859-1 Interesting guidelines here: https://crackstation.net/hashing-security.htm Regards Stuart Tremain IDFK Web Developments AUSTRALIA webdna@idfk.com.au On 03/10/2013, at 10:19 AM, Bill DeVaul wrote: > I agree that anything less than a salted hash is an enormous risk for = a compromised password. I don't know why a system would need to decrypt = a password except for a bad reason. =20 >=20 > Bill >=20 > On Oct 2, 2013, at 6:06 PM, Donovan Brooke wrote: >=20 >> Hi Tom, no time right now... but my .02=A2 below: >>=20 >> > can anyone tell me what algorithm is used? >>=20 >>=20 >> You could probably find this out... but it's against WSC's policy to = talk about this publicly.=20 >>=20 >>=20 >> > Also how are other people handing password storage? >>=20 >>=20 >> There is a school of thought that passwords should be a one-way only = hash... which ideally, I agree.=20 >> [encrypt] without a seed value does indeed produce the same value.. = but there is also [encrypt method=3Dapop].. which is MD5... you could = also use [Shell] to access higher-bit hash techniques.. but basically, = they'd all work. =20 >>=20 >> It's the random-per-password salting that counts the most I think.=20 >>=20 >> Donovan >>=20 >>=20 >> =20 >>> --------------------------------------------------------- This = message is sent to you because you are subscribed to the mailing list = . To unsubscribe, E-mail to: = archives: = http://mail.webdna.us/list/talk@webdna.us Bug Reporting: = support@webdna.us >>=20 >> --------------------------------------------------------- This = message is sent to you because you are subscribed to the mailing list . = To unsubscribe, E-mail to: archives: = http://mail.webdna.us/list/talk@webdna.us Bug Reporting: = support@webdna.us > --------------------------------------------------------- This message = is sent to you because you are subscribed to the mailing list . To = unsubscribe, E-mail to: archives: = http://mail.webdna.us/list/talk@webdna.us Bug Reporting: = support@webdna.us --Apple-Mail=_6B24514A-B49F-4FA4-B59D-DE17A0B70E11 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=iso-8859-1 Interesting guidelines here:



Regards

Stuart = Tremain
IDFK Web Developments
AUSTRALIA




On 03/10/2013, at 10:19 AM, Bill DeVaul <wdevaul@gmail.com> = wrote:

I agree that anything less than = a salted hash is an enormous risk for a compromised password.  I = don't know why a system would need to decrypt a password except for a = bad reason.  

Bill

On = Oct 2, 2013, at 6:06 PM, Donovan Brooke <dbrooke@webdna.us> = wrote:

 Hi Tom, no time right now... but my .02=A2 = below:

> can anyone tell me what algorithm is = used?


You could probably find this out... but it's against = WSC's policy to talk about this publicly. =


> Also how are other people handing = password storage?


There is a school of thought that passwords = should be a one-way only hash... which ideally, I agree.
[encrypt] = without a seed value does indeed produce the same value.. but there is = also [encrypt method=3Dapop].. which is MD5... you could also use = [Shell] to access higher-bit hash techniques.. but basically, they'd all = work. 

It's the random-per-password salting that counts the = most I think.

Donovan


  =   
--------------------------------------------------------- = This message is sent to you because you are subscribed to the mailing = list <talk@webdna.us>. To = unsubscribe, E-mail to: <talk-leave@webdna.us>archives:= http://mail.webdna.us/l= ist/talk@webdna.us Bug Reporting: support@webdna.us =

--------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: archives: http://mail.webdna.us/l= ist/talk@webdna.us Bug Reporting: support@webdna.us
--------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: archives: http://mail.webdna.us/l= ist/talk@webdna.us Bug Reporting: support@webdna.us

= --Apple-Mail=_6B24514A-B49F-4FA4-B59D-DE17A0B70E11-- Associated Messages, from the most recent to the oldest:

    
  1. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  2. Re: [WebDNA] Best practice re: password storage (Tom Duke 2013)
  3. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  4. Re: [WebDNA] Best practice re: password storage (WebDNA 2013)
  5. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  6. Re: [WebDNA] Best practice re: password storage (WebDNA 2013)
  7. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  8. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  9. Re: [WebDNA] Best practice re: password storage (WebDNA 2013)
  10. Re: [WebDNA] Best practice re: password storage (Bill DeVaul 2013)
  11. Re: [WebDNA] Best practice re: password storage (Donovan Brooke 2013)
  12. Re: [WebDNA] Best practice re: password storage (Stuart Tremain 2013)
  13. Re: [WebDNA] Best practice re: password storage (Tom Duke 2013)
  14. Re: [WebDNA] Best practice re: password storage (Stuart Tremain 2013)
  15. Re: [WebDNA] Best practice re: password storage (Tom Duke 2013)
  16. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  17. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  18. Re: [WebDNA] Best practice re: password storage (Stuart Tremain 2013)
  19. Re: [WebDNA] Best practice re: password storage (Tom Duke 2013)
  20. Re: [WebDNA] Best practice re: password storage (Dan Strong 2013)
  21. Re: [WebDNA] Best practice re: password storage (Stuart Tremain 2013)
  22. [WebDNA] Best practice re: password storage (Tom Duke 2013)
--Apple-Mail=_6B24514A-B49F-4FA4-B59D-DE17A0B70E11 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=iso-8859-1 Interesting guidelines here: https://crackstation.net/hashing-security.htm Regards Stuart Tremain IDFK Web Developments AUSTRALIA webdna@idfk.com.au On 03/10/2013, at 10:19 AM, Bill DeVaul wrote: > I agree that anything less than a salted hash is an enormous risk for = a compromised password. I don't know why a system would need to decrypt = a password except for a bad reason. =20 >=20 > Bill >=20 > On Oct 2, 2013, at 6:06 PM, Donovan Brooke wrote: >=20 >> Hi Tom, no time right now... but my .02=A2 below: >>=20 >> > can anyone tell me what algorithm is used? >>=20 >>=20 >> You could probably find this out... but it's against WSC's policy to = talk about this publicly.=20 >>=20 >>=20 >> > Also how are other people handing password storage? >>=20 >>=20 >> There is a school of thought that passwords should be a one-way only = hash... which ideally, I agree.=20 >> [encrypt] without a seed value does indeed produce the same value.. = but there is also [encrypt method=3Dapop].. which is MD5... you could = also use [shell] to access higher-bit hash techniques.. but basically, = they'd all work. =20 >>=20 >> It's the random-per-password salting that counts the most I think.=20 >>=20 >> Donovan >>=20 >>=20 >> =20 >>> --------------------------------------------------------- This = message is sent to you because you are subscribed to the mailing list = . To unsubscribe, E-mail to: = archives: = http://mail.webdna.us/list/talk@webdna.us Bug Reporting: = support@webdna.us >>=20 >> --------------------------------------------------------- This = message is sent to you because you are subscribed to the mailing list . = To unsubscribe, E-mail to: archives: = http://mail.webdna.us/list/talk@webdna.us Bug Reporting: = support@webdna.us > --------------------------------------------------------- This message = is sent to you because you are subscribed to the mailing list . To = unsubscribe, E-mail to: archives: = http://mail.webdna.us/list/talk@webdna.us Bug Reporting: = support@webdna.us --Apple-Mail=_6B24514A-B49F-4FA4-B59D-DE17A0B70E11 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=iso-8859-1 Interesting guidelines here:



Regards

Stuart = Tremain
IDFK Web Developments
AUSTRALIA




On 03/10/2013, at 10:19 AM, Bill DeVaul <wdevaul@gmail.com> = wrote:

I agree that anything less than = a salted hash is an enormous risk for a compromised password.  I = don't know why a system would need to decrypt a password except for a = bad reason.  

Bill

On = Oct 2, 2013, at 6:06 PM, Donovan Brooke <dbrooke@webdna.us> = wrote:

 Hi Tom, no time right now... but my .02=A2 = below:

> can anyone tell me what algorithm is = used?


You could probably find this out... but it's against = WSC's policy to talk about this publicly. =


> Also how are other people handing = password storage?


There is a school of thought that passwords = should be a one-way only hash... which ideally, I agree.
[encrypt] = without a seed value does indeed produce the same value.. but there is = also [encrypt method=3Dapop].. which is MD5... you could also use = [shell] to access higher-bit hash techniques.. but basically, they'd all = work. 

It's the random-per-password salting that counts the = most I think.

Donovan


  =   
--------------------------------------------------------- = This message is sent to you because you are subscribed to the mailing = list <talk@webdna.us>. To = unsubscribe, E-mail to: <talk-leave@webdna.us>archives:= http://mail.webdna.us/l= ist/talk@webdna.us Bug Reporting: support@webdna.us =

--------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: archives: http://mail.webdna.us/l= ist/talk@webdna.us Bug Reporting: support@webdna.us
--------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: archives: http://mail.webdna.us/l= ist/talk@webdna.us Bug Reporting: support@webdna.us

= --Apple-Mail=_6B24514A-B49F-4FA4-B59D-DE17A0B70E11-- WebDNA

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

WebCat B13 Mac CGI -- Frames question (1997) DB approach question (2000) normal users.db calls ... (1998) [lookup] still not working (1998) WebCat2b13MacPlugin - [math][date][/math] problem (1997) SSL PROBLEM (1999) Error Log.db --however (1997) Frames (1997) 'The List" (2006) grep is really pathetic sometimes (2003) Random Order Sort? (2000) [WebDNA] Anyone submitted SoAP info in TCPSEND? (2017) [WebDNA] Competitors! (2008) Store results of GetChars? (2003) Tab Charactor (1997) TCP Connect (2000) Can't load tmpl files (1997) Not really WebCat (1997) searching more then one (1999) Summing fields (1997)