• ScottPletcher (11/20/2014)


    No, DBAs should not know and definitely not store end user passwords, period.

    App passwords are a different matter, and it can depend on the app. But stored passwords should always be encrypted, and the decrypt key known by as few people possible, period. In a true emergency, one of those people can make it available to others as needed, then the password changed after the emergency has passed.

    +1000