From: Fred Phillips Date: 2008-08-28T07:11:24+09:00 Subject: Re: encrypting password on form submit? --DSayHWYpDlRfCAAQ Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu Aug 28 01:19:07 2008, Amanda .. wrote: > Fred Phillips wrote: > > This will have to be done with client=E2=80=90side scripting such as > > Javascript, not server=E2=80=90side Ruby. >=20 > okay well, since I haven't used much javascript, particularly with Ruby,= =20 > could you help me out with how I would use Javascript for this? I'm=20 > guessing I would have to call a method when I submit the form and get=20 > the string from the password box and encrypt it? >=20 >=20 > No idea how to do this really..any guidance would be great :) Even if I could, I wouldn=E2=80=99t. As it has been said, encrypting like t= his is a _bad_ idea. You really need to encrypt _after_ the form has been sent using Ruby server=E2=80=90side, before it is put into the database. Ta= ke a look at this[1] module for secure password encryption in Ruby. [1] http://www.zacharyfox.com/blog/ruby-on-rails/password-hashing --=20 Fred O. Phillips http://fophillips.org BBC7 7572 755F 83E0 3209 504A E4F7 874F 1545 9D41 --DSayHWYpDlRfCAAQ Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (GNU/Linux) iEYEARECAAYFAki10gQACgkQ5PeHTxVFnUFJRACgxruMdrzreNZWIOYEePshIQvc eN8An3ddnpcrCiqQ80WvwtapxYvjtOXU =NE6w -----END PGP SIGNATURE----- --DSayHWYpDlRfCAAQ--