Re: [Active4d-dev] How to store encrypted passwords in database-backend

2018-02-07 Thread Bart Alcorn
Here is an article that does a rather good job of describing the basics of salting and hashing passwords. Obviously not 4D centric, but the process itself is well explained. https://crackstation.net/hashing-security.htm Hope this helps! ~ Bart A

[Active4d-dev] How to store encrypted passwords in database-backend

2018-02-07 Thread Norbert Pfaff
Hi, one of our customers has had a security check, which included also our web-app. They write our passwords are not encrypted in the database, so that if aggressor has access to the preferences of a user, he can see the password in the html-code. They say we should save the password as a one-