Re: encryption
| From: | Chris Adams | Date: | Mon, 26 Jun 2000 17:41:04 +0000 |
| Subject: | Re: encryption | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-3146@lists.php.net to get a copy of this message | ||
[Fix your quoting]
> At 12:09 26-06-00 -0400, you wrote:
> >On Mon, Jun 26, 2000 at 11:31:59AM -0300, Martin A. Marques wrote:
> > > Is there a way to encrypt a string in PHP? Like a password column, and
> > later
> > > verify with the same encryption test?
> >
> >I always use store the md5() of the password, and then use md5 when a
> >password is
> >submitted to compare to the hash in the DB. There is also a crypt()
> >fucntion, but
> >I've never used it.
>
> So how would you decrypt the string?
With md5() and crypt(), you can't. This is actually A Good Thing(tm) with passwords - you can
see if
md5($UserSuppliedPassword) == $StoredMD5Hash to determine whether they entered the same password but
anyone who discovers a security hole on your server can't do something as simple as
"SELECT
Username, Password FROM Users" to get a list of passwords to go shopping with.
If you aren't just storing passwords and need to get the original text back, use the mcrypt
functions.