Why are plain text passwords bad, and how do I convince my boss that his treasured websites are in jeopardy?

后端 未结 9 2168
慢半拍i
慢半拍i 2020-11-27 15:53

I\'ve always been of the impression that storing passwords in a database as plain text is (as someone else here put it) a Very Bad Thing™.

Historically, most of our

9条回答
  •  野趣味
    野趣味 (楼主)
    2020-11-27 16:24

    Tell him to consider that in many companies, security problems come from inside rather than out.

    Now ask him how he's going to explain to his customers how hackers have stolen their passwords (which no doubt they used elsewhere) next time he has to fire someone for some reason.

    Also ask him how much he thinks his customers would like to know that their passwords are visible to anyone with read access to the database.

提交回复
热议问题