Re: WAYS OF AUTHENICATION - open discussion
| From: | Manuel Enrique Garcia Cuesta | Date: | Mon, 06 Nov 2000 19:00:15 +0000 |
| Subject: | Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23959@lists.php.net to get a copy of this message | ||
=== Thomas Deliduka escribia
(Mon, Nov 06, 2000 at 10:33:12AM -0500):
> Hmm, how do you decode md5? And when you encode a string, is it always the
> same string so you just encode it to check against the db? If it's always
> the same string when encoded, is is possible to break the code? I'm
> clueless in that respect.
As far as I know, md5 is still safe enough to use for
such purposes. An md5 hash cannot (presumably ) be decrypted,
and the function that calculates it produces identical outputs
to identical inputs. It's still possible to craft two different
input messages that produce the same hash, but (again as far as
I know ) it's not yet possible to, given a certain message,
devise another message that gives the same hash as the former.
Boy don't you have to thread lightly when you talk about
encryption :)
> > I hope more people will have something to say concerning security of web
> > sites.
>
> I don't know, best security is put it behind an ssl layer. My methodology I
> described before is used in a control panel that's behind a secure server.
Agreed.
>
> --
>
> Thomas Deliduka
> IT Manager
> -------------------------
> New Eve Media
> The Solution To Your Internet Angst
> http://www.neweve.com/
>
Manuel Garcia