Everywhere i have looked at login's and how to deal with them, or tutorials is just showing me compare to plain text.
I know never to store a plain text password in the database.
I am just asking if there is any material i can read or look at that has a general standardized way of storing password at a semi-commercial level.
I'm asking due to creating a application myself, and wish to have good security practices from the start, so as to improve on them further in my IT life.
Things i am assuming
- Encrypt the password and store it
- Upon logging in Encypt the password and compare the two.
I just want to further my knowledge for a more commercial level login system, instead of learning about plain text logins.. Any sources would be much appreciated.