Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SScrypto framework




On 13 Feb '08, at 9:09 AM, Stephen Hoffman wrote:

Safest is to not store the password. At all.

Second safest is to store a one-way (non-reversible, cryptographic) hash (digest). SHA-1 or otherwise, and with associated data (the user and some other known but varying data) incorporated into the input to reduce the exposure to rainbow table attacks.

That's a good answer for a server app, that needs to authenticate users. But I was assuming this code was part of a client app, doing something like saving the user's login password to avoid asking for it every time. In which case the Keychain is the right solution.


—Jens_______________________________________________

Cocoa-dev mailing list (email@hidden)

Please do not post admin requests or moderator comments to the list.
Contact the moderators at cocoa-dev-admins(at)lists.apple.com

Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/cocoa-dev/email@hidden

This email sent to email@hidden
References: 
 >Re: SScrypto framework (From: Stephen Hoffman <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.