If someone gets complete access to your database, you're pretty much hosed. Any encryption method that allows decryption can eventually be cracked by someone with enough time and determination. That's probably a lot easier than getting into the database through all that security, anyway.
The best practice is to really not store the entire number at all.



Joined: 08/07/2007