Doc #55215 [Com]: md5 page should display a warning not to be used for passwords

From: Date: Sun, 17 Jul 2011 10:50:35 +0000
Subject: Doc #55215 [Com]: md5 page should display a warning not to be used for passwords
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-6894@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=55215&edit=1 ID: 55215 Comment by: tyrael@php.net Reported by: ss23 at ss23 dot geek dot nz Summary: md5 page should display a warning not to be used for passwords Status: Closed Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant Assigned To: frozenfire Block user comment: N Private report: N New Comment: maybe we should mention that there are pre-computed databases(rainbow tables) and online services for md5/sha1 lookups, so in the majority of the password the brute forcing is already done. it would be also useful to mention if somehow you need to use any of the fast algos, you should salt the password before hashing. what do you think? Tyrael Previous Comments: ------------------------------------------------------------------------ [2011-07-16 23:47:46] frozenfire@php.net This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Other than a few tweaks to potentially be made, this is resolved. ------------------------------------------------------------------------ [2011-07-16 22:23:46] frozenfire@php.net Automatic comment from SVN on behalf of frozenfire Revision: http://svn.php.net/viewvc/?view=revision&revision=313306 Log: Added a "Password Hashing" faq, and notes to md5 and sha1 functions. Relates to bug #55215. ------------------------------------------------------------------------ [2011-07-15 12:51:01] joey@php.net It might also be nice to include a reference to a good explanation of why it's not, for example, Thomas Ptacek's article from a few years back. ------------------------------------------------------------------------ [2011-07-15 12:44:40] ss23 at ss23 dot geek dot nz Description: ------------ Currently, far too many users think that md5() is suitable for storing passwords in their database. A warning that informs them its not, along with a link to an appropriate replacement like crypt() would help. This could be appropriate for pages likes sha1() and hash() too. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=55215&edit=1

« previous php.doc.bugs (#6894) next »