Doc #55215 [Com]: md5 page should display a warning not to be used for passwords
| From: | tyrael@php.net | Date: | Sun, 17 Jul 2011 10:50:35 +0000 |
| Subject: | Doc #55215 [Com]: md5 page should display a warning not to be used for passwords | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-6894@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55215&edit=1
ID: 55215
Comment by: tyrael@php.net
Reported by: ss23 at ss23 dot geek dot nz
Summary: md5 page should display a warning not to be used for
passwords
Status: Closed
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
Assigned To: frozenfire
Block user comment: N
Private report: N
New Comment:
maybe we should mention that there are pre-computed databases(rainbow tables) and
online services for md5/sha1 lookups, so in the majority of the password the brute
forcing is already done.
it would be also useful to mention if somehow you need to use any of the fast
algos, you should salt the password before hashing.
what do you think?
Tyrael
Previous Comments:
------------------------------------------------------------------------
[2011-07-16 23:47:46] frozenfire@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Other than a few tweaks to potentially be made, this is resolved.
------------------------------------------------------------------------
[2011-07-16 22:23:46] frozenfire@php.net
Automatic comment from SVN on behalf of frozenfire
Revision: http://svn.php.net/viewvc/?view=revision&revision=313306
Log: Added a "Password Hashing" faq, and notes to md5 and sha1 functions. Relates
to bug #55215.
------------------------------------------------------------------------
[2011-07-15 12:51:01] joey@php.net
It might also be nice to include a reference to a good explanation of why it's
not, for example, Thomas Ptacek's article from a few years back.
------------------------------------------------------------------------
[2011-07-15 12:44:40] ss23 at ss23 dot geek dot nz
Description:
------------
Currently, far too many users think that md5() is suitable for storing passwords
in their database. A warning that informs them its not, along with a link to an
appropriate replacement like crypt() would help.
This could be appropriate for pages likes sha1() and hash() too.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=55215&edit=1