The government organisation that I work for pays
alot of money to a company to supply and host a specific web service.
I just discovered (by having to reset my password) that the passwords are not being hashed (because the reset service emailed me my current password in plain text).
Does anyone have an authoritive link that I can use in my email to my boss, stating that hashed passwords are basically a "101" of web security? i.e. something that he can use to tell the other company that their service is not good enough
If the government agency takes money online, PCI compliance (http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Secu...)
FIMSA: http://en.wikipedia.org/wiki/Federal_Information_Security_Ma...
FIPS 140-2: http://en.wikipedia.org/wiki/FIPS_140-2