Password Problem
Posted in 2000
Topics: Security, Permissions & Auditing
Hi, I am wondering what would be the best technique for storing a user's password. Here are the details: We have a web system, and in our database a member has an account and a password, now what I need to know is how can I store the password so that even the administrator's can not see it? Does Informix have a password protect? If so how do I use it and how does it work? Or do I need to have a separate database for the account # and password and revoke all privileges? Any and all comments and experience is appreciated Thank you Jordan jbruce@asaglobalserv.com
What level of security are you trying to achieve? If you are looking for a reasonable level of security, then I recommend that you not store passwords in the database at all, but instead us a cryptographically strong hash algorithm --such as SHA1-- and store the hash. When someone tries to login, you hash the password they give and compare that to the hash stored in the database. A cryptographically strong hashing routine has the property that given a hash it is a "hard problem" to reconstruct the password from which it was derived; moreover, a good routine is fast, easily implemented, and provides a vast number of unique hashes (there are 2^160 different hashes). SHA1 has these properties. This approach has a couple of advantages (provided a good hashing routine is selected). The table can be maintained with the usual access permissions; and the passphrases are not actually stored in the system. Moreover, all the hashes are the same length: 160 bits. SHA1 is free, approved by the FED's (if that is any consideration), and there is lots of code out there that implements it: C, C++, JAVA, PASCAL, etc. Cheers-- Charles ASA GSI <jbruce@asaglobalserv.com> wrote in article <UPKz5.29820$Z2.435862@nnrp1.uunet.ca>... > Hi, > > I am wondering what would be the best technique for storing a user's > password. Here are the details: > We have a web system, and in our database a member has an account and a > password, now what I need to know is how can I store the password so that > even the administrator's can not see it? Does Informix have a password > protect? If so how do I use it and how does it work? Or do I need to have > a separate database for the account # and password and revoke all > privileges? > > Any and all comments and experience is appreciated > Thank you > > Jordan > jbruce@asaglobalserv.com > > > >