2 ms·
It seems this system uses your scheme, except that instead of getting the key from administrator input, it computes it from the first K passwords it gets using
by devit 11y ago
It seems this system uses your scheme, except that instead of getting the key from administrator input, it computes it from the first K passwords it gets using a secret sharing scheme.
The advantage is that the administrator doesn't need to manually intervene, the disadvantage is that you can't verify passwords (in a way that is more secure than just verifying hashes) until you get at least K correct login attempts.
If the goal is only to defend against SQL injection, a much simpler solution is to just put the key outside the database, for instance in the configuration or source of the application.
- petejansson 11y agoPlease don't ever put keys in the source of an application.