3 ms·
There's a security issue with this idea obviously. If I'm not mistaken, the whole point of hashing passwords is so that a loss of the user database in some way
by ehsanul 17y ago
There's a security issue with this idea obviously. If I'm not mistaken, the whole point of hashing passwords is so that a loss of the user database in some way does not compromise any accounts. You might as well store passwords in plain text if you allow hashed passwords as passwords.
It might just be acceptable though, since almost nobody would guess that a hashed password would be accepted as a password. That is, unless they have access to the controller source code too, and check it out (as you'd assume since the database itself has been compromised).
A better solution may be to create a second temporary password, hashed in another field in the database, and wipe it out when you're done.
It's fine to use an extremely long master password too, making sure it's stored as a bcrypt hash or something. Just run the calculations to make sure that it couldn't be broken in 2^999 years.
- charliepark 17y agoHrm. You're right. Secondary benefit of the hashing is so that a user's re-used password isn't compromised for other sites, but ... yeah. Your dynamically-generated temporary password is probably a better way to go about it. Or the hashed master password. Thanks.