Re: Encrypting a column (password column)

From: Date: Wed, 20 Dec 2000 14:08:53 +0000
Subject: Re: Encrypting a column (password column)
Groups: php.db 
Request: Send a blank email to php-db+get-5359@lists.php.net to get a copy of this message
"Noah Spitzer-Williams" <noahsw@cyberdude.com> wrote: > > Hey, i have a user database in which one of the columns of a table is their > password. however i would like to have this encrypted just so when i look at > it using somethin like phpmyadmin, their password isnt visible. is there an > easy way to do this? > Not to disagree with anything posted by others, but may I make a couple of suggestions? First, while using the MySQL "password()" function is perfectly fine, you should be aware that not all SQL databases support this feature. So if you let MySQL do the encryption, you will perhaps encounter problems if you later want to run your code on DB2 or Oracle or something else. I recommend using the md5() function that's built into PHP itself. This way you know that your code is database-portable. Simply call md5() to encrypt the string before creating the SQL statement that writes it into the database. Second, you should concatenate the login name and some special character ahead of the password before encryption. The reason for this is so that two people who happen to select the same password won't get the same encrypted string. This strengthens your security in case someone manages to gain access to the encrypted fields in the database. Here's an example of how to store the crypted string, using both of my suggestions above. Assume that $login and $password are the cleartext versions supplied to your code. $concat = $login . "\n" . $password; $crypto = md5($concat); $sql = "INSERT INTO user_table (login,passwd) VALUES ('"; $sql .= $login . "','" . $crypto . "')"; # Execute the SQL here. If you instead needed to update, the SQL would be $sql = "UPDATE user_table SET passwd='" . $crypto; $sql .= "' WHERE login='" . $login . "'"; Now, during login when it's time to compare the user-entered password with the one in the database, you simply do this: $concat = $login . "\n" . $password_they_entered; $entered_crypto = md5($concat); # Use any desired means to get the value of the # 'passwd' column from the database into the local # variable $crypto. if ($entered_crypto == $crypto) { # Good login } else { # Bad password } In the future, I'm hopeful that PHP can support the SHA1 one-way encryption function. It's my understanding that this is stronger even than MD5. For now, however, MD5 is considered strong enough encryption for all but the most sensitive data. The weak link in the system I've outlined above is that the cleartext password is still sent on the wire at every login. You may wish to consider using HTTPS if your application is e-commerce or otherwise involves sensitive financial data. Hope this helps! Scott Courtney courtney@4th.com

« previous php.db (#5359) next »