Re: Re[2]: [PHP] Credit Card suggestions
| From: | Robert Parker | Date: | Wed, 14 Aug 2002 06:36:16 +0000 |
| Subject: | Re: Re[2]: [PHP] Credit Card suggestions | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-112360@lists.php.net to get a copy of this message | ||
On Tuesday 13 August 2002 12:20 pm, you wrote:
> Makes sense, except if you use upper and lowercase characters,
> numbers, and symbols (as you should for secure passwords). I
> would think that with these kind of passwords, storing the sheer
> number of posibilites would get slightly large. And I mean even
> if it is easy to break, it's more secure then storing them clear
> text.
>
> Adam Voigt
> adam.voigt@cryptocomm.com
Thing that really scares me about MD5 being used anywhere that's easily
accessible is what happens if 'pussycat' maps on to the same hash as
'H&3ph!3s09Zw'. The crackers don't need the original password just something
that generates the same hash.
Bob Parker