7 ms·
Easy User Authentication For Mobile Developers
- bigiain 15y ago"Also, we encrypt user passwords on our servers and we never return a password in the result of any query." Queue a link to _that_ bcrypt article... I wonder if they've got a reason not to only store a hash? And if so, I wonder if they've got infrastructure secure enough to store your users passwords in an apparently retrievable form? (I quite like Mozilla.org's guideline of storing the hashes in he database and the salts in the filesystem, to help ameliorate the consequences of an SQL injection attack...)
- jordanrw 15y agoHi, thank you for your inquiry. I'm one of the StackMob engineers that worked on this feature. The encryption is one-way and we are storing a hash only using bcrypt. We will update the post ASAP to be more clear.
- bigiain 15y agoGood to hear. Thanks for the response. I'd be interested to hear about your timeframe for "forgotten password" and "password reset", it's not really up to a "minimum viable product" without that.
- glenngillen 15y agoA previous employer took 10 years to implement both of those, and was very profitably in business during that time. You'd be surprised what can constitute a "minimum" viable product.
- janaboruta 15y agoWere you referring to these guidelines? https://wiki.mozilla.org/WebAppSec/Secure_Coding_Guidelines#Password_Storage https://wiki.mozilla.org/WebAppSec/Secure_Coding_Guidelines#...
- bigiain 15y agoYes indeed. Thanks for the link...
- buro9 15y agoA question I'm struggling with at the moment for my own project, is whether allowing the password to pass through the hands of a third party developer is even wise?
- claus_z 15y agoSeems in part very similar to parse.com
- dustineichler 15y ago1. Should you even bother using this if you can't implement NSURLConnection based authentication. No. 2. The point of this is lost on me. Why would I use this?