Not sure what you mean by a SELECT grab, but I usually HASH() my passwords.
Of course this means you can never "tell" a user their forgotten password,
you'll have to use a verified reassignment process.

--------------
Ian Skinner
Web Programmer
BloodSource
www.BloodSource.org
Sacramento, CA

-----Original Message-----
From: C. Hatton Humphrey [mailto:[EMAIL PROTECTED]
Sent: Monday, December 15, 2003 10:43 AM
To: CF-Talk
Subject: Scrambling Data

I am working out a database schema for an intranet and need to figure out
some way to mask the password field in the users table from simple SELECT
grabs.

I know that CF has some built-in encryption tools but I can't remember what
they are.  Can someone point me in the right direction?

At this moment I'm just trying to figure out what to store in the database.
I know I'll need a field for the password but do I need to also provide a
field for a key or key pair?

Thanks!
Hatton

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.548 / Virus Database: 341 - Release Date: 12/5/2003
   _____
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Reply via email to