This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
User talk:Jmanico
From OWASP
Cryptographic Storage Cheat Sheet
Jim, I've been just looking at Cryptographic Storage Cheat Sheet and it's missing direct requirement on ensuring message integrity. It's kind of mentioned in the section on authenticated encryption modes, but without mentioning HMAC it's like describing Rolls-Royce without mentioning Ford :) And the problem seems to be wide-spread (as I've just wrote here). Pawel Krawczyk 21:47, 21 January 2013 (UTC)