> I give up you win but, if you get hacked you will know
>
If someone hacks one of my servers they would still need to crack the encrypted stored passwords in my database ??
It is far more likely someone installs some stupid browser addon which records keystrokes and then sends it over to some 3rd party which basically abused the users lack of security knowledge for browsers on their end.
I actually know a little about this ??
Yea, I worked in the military cybersecurity world for a while... at least until I publicly supported Edward Snowden.
I am in the process of getting encrypted database passwords done. And still developing a draw a secret password system too... so much to do, and so little time.
How do you encrypt the passwords for your database? I assume you are using symmetric encryption. Where do you store the keys?