The other posters are correct. Now that you're using SSL to encrypt the transmission of the password, make sure you're hashing it with a good algorithm and salt so it's protected when it's 休息, too...
散列客户端,怎么了?
让我告诉你一个小实验。
走到公司食堂的电脑前,打开浏览器进入公司网站登录页面(https)。
按 F12,单击网络标签,勾选持久日志,最小化控制台,但保持网页打开登录页面。
坐下来吃午饭。看着员工一个接一个地登录公司网站,做个好员工。
Finish lunch, sit down at computer bring up network tab and see every single username and password in plain text in the form bodys.
No special tools, no special knowledge, no fancy hacking hardware, no keyloggers just good old F12.
But hey, keep thinking all you need is SSL. The bad guys will love you for it.