If a password is stored in an encrypted format in the database, then one should not be able to use the 32bit encrypted number to login
Going along the lines of maintaining a secure password in the database, the encrypted password is only secure if it is meaningless to all except the server authentication process.Otherwise whats the purpose of encryption?
As a test, If you copy the 32 bit encrypted number from the database table and use it as the password when you login, the system accepts it as a valid password.This is wrong, it should reject it and only allow the unencrypted password.
Therefore the password authentication process invalidates the encryption and makes what is perceived to be secure a password insecure
I hope I am making sense, because in my mind this is a serious problem