General security Question (Databases)

From: Date: Tue, 20 Mar 2001 11:11:29 +0000
Subject: General security Question (Databases)
Groups: php.general 
Request: Send a blank email to php-general+get-44720@lists.php.net to get a copy of this message
The examples of holding passwords in databases (i.e. mysql) tend to encrypt the password. Although this seems sensible (if not necessary) it douse mean that if a user forgets there password the normal solution is to generate a new random password and email it to them. Then I realised that this fafing about was all a bit unnecessary. Surly if security has been breached to the extent that the user table can be accesses chances are that the intruder could delete data from tables or even drop them. In fact the best solution is to set up proper database users rather than your own 'application' users. This way you can set it up (at database level) so that for 'Punters' they can only read most of the data and 'Administrators' have fuller access. So maybe the conclusion is there is no point in encryption passwords but there are very good reasons to have users an 'real' database users. What do you lot reckon. Ben. -- ben.2.edwards@bt.com (ben@work until end March) ben@videonetwork.org (ben@home)

« previous php.general (#44720) next »