Thanks for the input, looks like the 1-way hash will handle the problem nicely.
Oh, yes, you're right, if someone has got that far into the database they could do anything they want. What we're trying to avoid is a situation where someone would become aware of a UID and PWD and then go back...