4 ms·
had a good laugh when i saw this article. thx mithrandir :) passwords stored in the clear in server-side sessions => server hack compromises data. storing keys
by conformal 14y ago
had a good laugh when i saw this article. thx mithrandir :)
passwords stored in the clear in server-side sessions => server hack compromises data. storing keys server-side means admins can get into your data.
had a big lol at the use of blowfish ECB - use of any cipher's ECB mode for bulk encryption is asking for problems. they should be using CBC, CTR, LRW or, ideally, XTS modes.
- graue 14y agoUsing server-side encryption at all means admins can get into your data, does it not? They can modify the source code so that when the server decrypts/encrypts the data at your request, it also saves a copy in cleartext. How would you avoid this without encrypting on the client side?