Re: passwords

From: Date: Fri, 07 Jul 2000 17:47:53 +0000
Subject: Re: passwords
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-5422@lists.php.net to get a copy of this message
> Chris Moyer <cmoyer@chekinc.com> wrote: > > 3) It's probably a lot easier to simply use an existing encryption > method, > > unless you're an encryption expert. > > What is the "existing encryption method"? For passwords? A function like crypt(). > Martin A. Marques <martin@math.unl.edu.ar> wrote: > > Use MD5!!!!! > > It's a string function! > > How dose the browser encrypt to send it? It doesn't. The server stores passwords as MD5 hashes and md5()s the user input before comparing. If you don't want cleartext being sent over the network, it's safest to use SSL as that's been tested heavily and will have the fewest problems with browser compatibility.

« previous php.general (#5422) next »