Re: passwords
| From: | Chris Adams | Date: | Fri, 07 Jul 2000 17:47:53 +0000 |
| Subject: | Re: passwords | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-5422@lists.php.net to get a copy of this message | ||
> Chris Moyer <cmoyer@chekinc.com> wrote:
> > 3) It's probably a lot easier to simply use an existing encryption
> method,
> > unless you're an encryption expert.
>
> What is the "existing encryption method"?
For passwords? A function like crypt().
> Martin A. Marques <martin@math.unl.edu.ar> wrote:
> > Use MD5!!!!!
> > It's a string function!
>
> How dose the browser encrypt to send it?
It doesn't. The server stores passwords as MD5 hashes and md5()s the user
input before comparing. If you don't want cleartext being sent over the
network, it's safest to use SSL as that's been tested heavily and will have
the fewest problems with browser compatibility.