Quote:
Originally Posted by Zachery
You could store the key and the encryption type in the database or in a file somewhere. Or even make it an extra option for two users to create their own keys to be shared with eachother.
Its more than possible to encrypt them so an external source who may gain access to your database will not be able to read their contents.
|
That's my point. If a person got access to the db, what is to prevent them from using the key itself.
All they would have to do is try different variations of encryptions, and arragements of the keys in relation to the data encrypted.
Whats worse, if they were a member at vbulletin.org, they will Know the arrangement of the keys, just by viewing this hack.