|
Use some variable, other than the user name, to salt the password before you hash it.
Emails are a big problem. Not only are they of great marketing value -- email and user data is an extortion bonanza. If you value your businesses reputation and brand goodwill you need to actively secure this data.
The email marketing is problematic. For a medium sized business, doing high volume mail outs, the Spam server rules create security gaps that you have to trust to others (mailers).
The other point is network, database server and script security -- how did the hackers breach the system's security?
|