|
|
|
|
|
by drm237
6314 days ago
|
|
True, two way hashing is better than nothing, but it's still less secure than one way hashing (with a per-user salt) for passwords. All you need if one rogue employee and they can decrypt everyone's password. It's just difficult to justify the added risk when there usually isn't a need to retrieve the original password. Edit: by "two way hashing" I meant encryption, not hashing. not sure where my brain was on that one... |
|