I recently saw the following message verbatim on an online application I use. The login is simply a login/password combination. There is no oauth, no two factor authentication, etc...
This sounds like bullshit to me, but I'm no security expert which is why I'm posting it here. Is this possibly true? If so, how would one go about securing their site this way?
To access our secure area, you must enter your Logon ID and Security Code. As a security precaution, we store your Security Code in our database in an encrypted format that even we cannot decode.