4 ms·
I believe that he's implying they would be hashed just like your password and used solely for verification with another system (like transaction authorization).
by TkTech 12y ago
I believe that he's implying they would be hashed just like your password and used solely for verification with another system (like transaction authorization).
- valarauca1 12y agoI don't think hashing an address is a very good way to store it, recovery might take a while. Likely the poster means person information. Name, date of birth, address, back up email, phone number should be encrypted. Even just using the users password as a key would be better then clear text.
- rplnt 12y agoWouldn't it be easier to "guess" the passwords then? If you know both input and output.
- valarauca1 12y agoIt wouldn't be difficult, but a bandage is better then leaving a gaping wound. Yes it would be better store a second salt and do a scrypt style password generation.