Re: encryption
| From: | Chris Adams | Date: | Mon, 26 Jun 2000 18:13:27 +0000 |
| Subject: | Re: encryption | ||
| References: | 1 2 3 4 5 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-3157@lists.php.net to get a copy of this message | ||
> On Mon, Jun 26, 2000 at 06:23:13PM +0100, Adam Charnock wrote:
> > So how would you decrypt the string?
> >
> > Adam
> >
>
> You don't... You store the md5 hash of the password. Then when a password is submitted,
> you create a md5 has of that and compare them. I think md5 is theoretically one-way
> encryption.
MD5 is definitely one-way encryption as an md5 hash is 128-bits regardless of the size of the input
data. The real benefit is that a) it is one way and b) t's computationally infeasible to
produce an
input that would produce a given hash. Someone who received a copy of a password list would still
have a really difficult time producing a password which would give the MD5 hash stored in that
password list.
Anyone who's really curious might find this page interesting:
http://www.ssh.fi/tech/crypto/intro.html#hash