Comment on The Database Programmer: Advanced Table Design: Secure Password ResetsComments−ars18yHe's fighting the wrong battle.He's sending the hash by email! And then working so hard at securing the wrong part of the process - with SSL of course, when email is not encrypted.
Comments
He's fighting the wrong battle.
He's sending the hash by email! And then working so hard at securing the wrong part of the process - with SSL of course, when email is not encrypted.