> > Is there a convention for obfuscating database passwords?
Hi David,
Most people run passwords through some sort of hashing function. That is,
databases almost never contain passwords in the clear, but instead store
the hashes of those passwords.
For example, I am almost positive that Amazon does not store its user's
passwords in the clear. *grin*
Storing clear-text passwords would be terrible from a security point of
view, since some people, despite being warned, use the same password for
everything that they do. And you can't trust the database provider not to
spill data every once in a while.
So hashing's probably the way to go. Common hash functions include MD5 or
SHA-1:
http://www.python.org/doc/lib/module-md5.html
http://www.python.org/doc/lib/module-sha.html
Pick one. *grin*
Avoid using a database-specific hash function, but use something standard
like MD5 or SHA-1, unless you really need to do something special. In
particular, MySQL's documentation recommends against using its own
internal PASSWORD() function, and recommends the other two hashing
functions, just because they warn that they're free to change the PASSWORD
implementation at any time:
http://dev.mysql.com/doc/mysql/en/application-password-use.html
I assume the same kind of warning applies to any other database.
Best of wishes!
_______________________________________________
Tutor maillist - [email protected]
http://mail.python.org/mailman/listinfo/tutor