Re: encryption

From: Date: Mon, 26 Jun 2000 17:41:04 +0000
Subject: Re: encryption
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-3146@lists.php.net to get a copy of this message
[Fix your quoting] > At 12:09 26-06-00 -0400, you wrote: > >On Mon, Jun 26, 2000 at 11:31:59AM -0300, Martin A. Marques wrote: > > > Is there a way to encrypt a string in PHP? Like a password column, and > > later > > > verify with the same encryption test? > > > >I always use store the md5() of the password, and then use md5 when a > >password is > >submitted to compare to the hash in the DB. There is also a crypt() > >fucntion, but > >I've never used it. > > So how would you decrypt the string? With md5() and crypt(), you can't. This is actually A Good Thing(tm) with passwords - you can see if md5($UserSuppliedPassword) == $StoredMD5Hash to determine whether they entered the same password but anyone who discovers a security hole on your server can't do something as simple as "SELECT Username, Password FROM Users" to get a list of passwords to go shopping with. If you aren't just storing passwords and need to get the original text back, use the mcrypt functions.

« previous php.general (#3146) next »