From e834dde50717f577f27f3de6c87d73eeb2e1239d Mon Sep 17 00:00:00 2001 From: Lars Wirzenius Date: Sun, 31 Mar 2019 18:41:46 +0300 Subject: Add: peppering of secrets --- yuck.mdwn | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/yuck.mdwn b/yuck.mdwn index 7908b01..352ccd9 100644 --- a/yuck.mdwn +++ b/yuck.mdwn @@ -128,7 +128,8 @@ reference in discussions. minimises damage if they leak. Credentials SHOULD be stored encrypted using a respected encryption algorithm (such as scrypt) and using per-credential salting. Or something stronger - may be implemented instead. + may be implemented instead. Additionally, all the credntial + records SHOULD be encrypted for an additional layer of defense. * (MFA) Yuck MUST support multi-factor authentication using secure factors. * (PROTOS) Yuck MUST use secure protocols to authenticate users -- cgit v1.2.1