3 ms·
1. You can store it on the client side in a cookie. 2. You can encrypt the passwords with a key outside of the database instead of hashing them. That means tha
by devit 8y ago
1. You can store it on the client side in a cookie.
2. You can encrypt the passwords with a key outside of the database instead of hashing them. That means that people can now login with a read-only compromise of both your app and the database, but chances are that such a compromise would be a full compromise anyway.
3. You can also not show them the current password, but instead generate another one and have them both be valid (until explicitly revoked)