4 ms·
You can encrypt it in the database, but my preference is to just reset the tokens if and when the DB is stolen. If they've managed to steal it, solid chance the
by FastEatSlow 5y ago
You can encrypt it in the database, but my preference is to just reset the tokens if and when the DB is stolen. If they've managed to steal it, solid chance they'll be able to decrypt it from the running db process or sniff through other infrastructure.
- awinter-py 5y agohow will I know when the DB is stolen?
- FastEatSlow 5y agoReally depends on your DB setup, ie if it's on a managed service or not. There's plenty of work done into intrusion detection if you're managing it.