RE: [PHP] How crypting passwords in DB
| From: | Maxim Maletsky | Date: | Fri, 22 Dec 2000 14:54:57 +0000 |
| Subject: | RE: [PHP] How crypting passwords in DB | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-31574@lists.php.net to get a copy of this message | ||
Yeah, sort of...
this is when you are inserting a user into the database.
you do what: you ask them to (sign up?) and they type the password they want
to use later on.
If you don't wish to have that password stored in the database as a plain
text you can then encrypted with the build-in SQL function PASSWORD().
This is EXACTLY the same as to have it plain, except the difference is when
someone steals your database he can't SEE the passwords there.
Are you asking about database or about the fields themselves (like in
hotmail when you type in your password but see only asterics (*)) ?
If your wuestion is "how to encrypt the passwords in the database" then
we're right: we are talking about it right now. If not then please describe
more specifically what you meant in your previous question and we will be
glad to answer you.
Cheers,
Maxim Maletsky
-----Original Message-----
From: ouldm@linux-at-business.com [mailto:ouldm@linux-at-business.com]
Sent: Friday, December 22, 2000 11:45 PM
To: Maxim Maletsky; php-general@lists.php.net
Subject: Re: [PHP] How crypting passwords in DB
Maxim Maletsky a écrit :
> there's a PASSWORD function in SQL Languages, for instance in mySQL qould
be
> :
>
> INSERT INTO users (username, password) VALUES ('$username',
> PASSWORD('$password'))
>
> and it will encrypt it for you.
>
> hope this was what you meant,
> Maxim Maletsky
>
> -----Original Message-----
> From: ouldm@linux-at-business.com [mailto:ouldm@linux-at-business.com]
> Sent: Friday, December 22, 2000 11:27 PM
> To: php-general@lists.php.net
> Subject: [PHP] How crypting passwords in DB
>
> Hello,
>
> I'm asking for how one can store crypted passwords in my database
> (Postgres).
> Actually I can see in clear the password of users authorized to access
> my site.
>
> Thanks
>
Excuse me I don't longuer understand!!
I'm new to all these area.
Is the following command is valid for known users (i.e. those I create by
hand
then attribute them passwords in the database)?
Or this is valid for any user visiting my site? For exemple: when he/she
enter
my site and click any things they find a pop-up for
"name" and "password" then they are directly saved in my database?
Excuse me.