Iโ€™m wondering if the recommended approach is to sa...
# lucee
s
Iโ€™m wondering if the recommended approach is to save the whole resulting string in the db or whether I should split the arguments (parallelism, memory, iterations)
e
I wouldn't save a password that is reversible to any database, ever, but that's me. As for how it's really up to you.
s
Itโ€™s not reversible as itโ€™s a hash but my concern is that it will be if I store those params with it haha
or not reversible but reproducible I should say
e
The general thought on security is, passwords are OKAY, and trust anyone with the password, but verify who they are anyway. Its why banks are now sending out texts or emails to the account holder with a date-time expiring code. Modern GPUs are really efficient at making games look nice and assembling/disassembling encryption. No matter what you do, password security is only as secure as you make it. Sooner or later even the most secure encryption of the day will be broken and encryption really is nothing more than that childish primary school crap of here is my new alphabet, now when I say "CKOW" I mean "Dog"!. ๐Ÿ™‚
s
Yeah it will have 2fa as well
๐Ÿ‘ 1
m
That CKOW won't hunt!
๐Ÿ˜… 1
๐Ÿ‘ 1
s
Thanks Andrea's!
*@Andreas
a
You are totally welcome!