Easy User Authentication For Mobile Developers
stackmob.com
stackmob.com
Queue a link to _that_ bcrypt article...
I wonder if they've got a reason not to only store a hash? And if so, I wonder if they've got infrastructure secure enough to store your users passwords in an apparently retrievable form?
(I quite like Mozilla.org's guideline of storing the hashes in he database and the salts in the filesystem, to help ameliorate the consequences of an SQL injection attack...)
I'd be interested to hear about your timeframe for "forgotten password" and "password reset", it's not really up to a "minimum viable product" without that.
You'd be surprised what can constitute a "minimum" viable product.