I suggest you ...

Hash&salt user-passwords

Skadate saves user-passwords in plaintext. This is a security flaw: if someone gains access to the database that person can see all those passwords.
I'd suggest that only a salted hash of the password is saved in database ("MD5(CONCAT('mypassword','somesalt'))").
Then also a "reset password"-functionality would be needed, since the originial password cannot be restored from the DB.
See also: http://www.techcrunch.com/2009/12/14/rockyou-hacked/

64 votes
Vote 0 votes Vote Vote
Vote
Sign in
Check!
(thinking…)
Reset
or sign in with
  • facebook
  • google
    Password icon
    I agree to the terms of service

    You'll receive a confirmation email with a link to create a password (optional).

    Signed in as (Sign out)
    You have left! (?) (thinking…)
    njamnjam shared this idea  ·   ·  Flag idea as inappropriate…  ·  Admin →

    17 comments

    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service

      You'll receive a confirmation email with a link to create a password (optional).

      Signed in as (Sign out)
      Submitting...

      Knowledge Base and Helpdesk