+ Reply to Thread
Results 1 to 2 of 2

Thread: The best encryption system?

  1. #1
    Twinkie is offline Banned Twinkie is an unknown quantity at this point
    Join Date
    Sep 2007
    Location
    Ft. Lauderdale, Florida
    Posts
    1,389

    The best encryption system?

    As far as I know, there are two "practical" ways to steal passwords, network sniffing and hacking the database. Hashing and using methods like the challenge-response system is meant to stop this possibility, but is there a way to secure both the client and the server equally? Salting a hashed database mean that you cannot salt submitted password with JavaScript and make a valid comparison. Salting with JavaScript means that you must store unsalted hashes in the database. Any unsalted hash is subject to a brute force attack, with a reasonable success rate for weak passwords. Is there an encryption system to not sacrifice security at either end?
    Last edited by Twinkie; 04-18-2009 at 07:59 PM.

  2. #2
    Steeevoe is offline x10 Sophmore Steeevoe is an unknown quantity at this point
    Join Date
    Feb 2009
    Location
    Leicestershire [UK]
    Posts
    103

    Re: The best encryption system?

    If a hacker wants your passwords, he will get em! I'm sure most out there want easy targets to hack just for fun.

    Use a salt that changes for every user that no-one knows or what no one can easily guess (not the username!), and has no iteration.

    You could hold the salt you are using in its normal state in your database. When the person logs in it has to be encrypted to its useable form with a small script . You could use MD5 in that script but keeping to one encryption technique does not increase complexity of things.

    Do some old types of encryption like a reversing every 5 out of 10 blocks of text, affine shift all the letters and increase all the numbers by 3, or even use one of the parts of your webpage to use as a one-time-pad to encrypt the text. As long as the salt stored in the db is like ten letters of an MD5(date());

    The best encryption method is one that no one ever has thought of and that no one knows about!
    Last edited by Steeevoe; 04-20-2009 at 12:38 PM.
    The above message was posted by a guy called Steevoe. We hope you enjoyed his comment

+ Reply to Thread

Similar Threads

  1. Replies: 22
    Last Post: 07-25-2008, 09:43 AM
  2. The History Of Gaming!
    By ashwinsinha in forum Gamer's Lounge
    Replies: 26
    Last Post: 03-29-2008, 05:54 PM
  3. What is Authentication
    By asadislam78 in forum Computers & Technology
    Replies: 1
    Last Post: 12-13-2007, 07:13 AM
  4. New PSP UPGADE
    By IamShipon1988 in forum Gamer's Lounge
    Replies: 4
    Last Post: 09-04-2005, 08:23 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
x10hosting free hosting for the masses
dedicated servers