|
I'm with Jon Prettyman. It is not best practice for a server to keep passwords in clear.
But i see no reason why Bob could not know the algorithim (and any necessary data) that the server uses to encrypt the passwords, and encrypt his before sending it...
O!
Hmmm...
Any comments?
=joaquin aka http://mylid.net/joaquin
|