Quote:

That sounds like a really bad idea.

You shouldn't try to hide the password. Instead make sure the user can only do what he is supposed to do with that password. What I mean is that you should limit the rights for that account on the server side. That way, even if they have the password and connect to your server they can only do what they are allowed to do(which is the same as the app would normaly do).




imagine this: an MMORPG, we need to write/change and delete(delete account) data. so anyone could just login and delete all other users, or just make his char "ubar"... hiding the password in this case is ESSENCIAL.


"Sometimes JCL reminds me of Notch, but more competent" ~ Kiyaku