jdiben
03-24-2005, 10:03 AM
Maybe I am missing the obvious but I can't understand the purpose of hashing passwords to store in a database. As I understand it if someone manages to access my database they will not be able to recover my users passwords and that makes perfect sense. My question is if someone is able to get to the hashed passwords that means that they already have full access to my database and all data within so why, at that point, would it matter if they can see the passwords?