3 ms·
How do companies keep messing this up. The cardinal rule of web application security is to NEVER store plain text passwords anywhere. The only time your applica
by scriptkiddy 8y ago
How do companies keep messing this up. The cardinal rule of web application security is to NEVER store plain text passwords anywhere. The only time your application should have access to plain text passwords is when it is hashing the password or verifying the password against a hash.
If you need to log all request data for some reason, strip the passwords out.
It really isn't difficult.
- qpiox 8y agoIn properly built software, the clear text password never leaves the client (browser in this case). There is no real need to have the password sent over the net.