PDA

View Full Version : Pci 8.4


PCI4Life
02-11-2008, 11:10 AM
"8.4 Encrypt all passwords during transmission and storage, on all system components"

Does the encrypted storage requirement also apply to customer account passwords on an e-commerce website?

Thanks.

DMertz
02-12-2008, 10:43 AM
Bottom line - yes. Passwords should be encrypted in storage and during transmission.

David Mertz
Partner
Compliance Security Partners, LLC
816 256-2125

HappyCat
02-13-2008, 03:35 AM
Just a quick note that hashing passwords is significantly easier than encryption as it avoids all the key management issues related to encryption.

jbhall56
02-15-2008, 03:36 PM
Just a quick note that hashing passwords is significantly easier than encryption as it avoids all the key management issues related to encryption.

Yes, but hashing is susceptible to rainbow attacks, so nothing is perfect.