Is an 'if password == XXXXXXX' enough for minimum security?

Posted by Prof Plum on Programmers See other posts from Programmers or by Prof Plum
Published on 2011-02-18T15:41:56Z Indexed on 2011/02/18 23:33 UTC
Read the original article Hit count: 234

Filed under:
|
|

If I create a login for an app that has middle to low security risk (in other words, its not a banking app or anything), is it acceptable for me to verify a password entered by the user by just saying something like:

if(enteredPassword == verifiedPassword)
     SendToRestrictedArea();
else
     DisplayPasswordUnknownMessage();

It seems to easy to be effective, but I certainly would not mind if that was all that was required. Is a simple check on username/password combo enough?

Update: The particular project happens to be a web service, the verification is entirely server side, and it is not open-source. Does the domain change how you would deal with this?

© Programmers or respective owner

Related posts about security

Related posts about passwords