Hi there,
I’ve got a client who is very concerned about the security of their members’ personal information. I get the impression standard fields like passwords are encrypted by default (using the Security Encryption Key?), but what about custom fields? Things like their home address, phone number, bio, etc.
They’re currently storing their info in an unencrypted excel file on one of their home computers, and I’m trying to convince them it would be more secure to store their membership info using s2member. What exactly would an attacker need in order to gain access to the unencrypted user info?