Re: passwords

From: Date: Fri, 07 Jul 2000 17:52:05 +0000
Subject: Re: passwords
References: 1 2 3 4  Groups: php.general 
Request: Send a blank email to php-general+get-5423@lists.php.net to get a copy of this message
> thanks guys; let's see if i got it: i md5-encrypt the password string once > and store the resulting string. i change the form method to post. as soon as > my script gets the username and password it encrypts the password again and > checks against the stored one. if they match and i don't want to work with > cookies then i pass the username and encrypted password from page to page. I'd avoid putting username/password in the form unless there's no alternative. It'd be safer to use the PHP4 session library (which can be used without cookies) for this sort of thing. > btw, there doesn't seem to be a single built-in decryption function in php, > is there? not necessarily a bad thing... Not in the core, no. There's the entire mcrypt library (See Encryption Functions in the manual) which provides a number of encryption algorithms. (BTW - md5() isn't encryption. It's a cryptographic hash because you can never retrieve the input.)

« previous php.general (#5423) next »