Re: Encryption
| From: | Dan Krumlauf | Date: | Thu, 13 Jul 2000 00:09:38 +0000 |
| Subject: | Re: Encryption | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-6341@lists.php.net to get a copy of this message | ||
Richard Heyes wrote:
>
> Oops. Just found the encryption section of the manual...
>
> But I still have to store the key in the script though yes? Can't be
> very secure.
>
> --
> Richard Heyes
> http://www.heyes-computing.net/scripts/
> Plain text email only please!
>
> > -----Original Message-----
> > From: Richard Heyes [mailto:php@heyes-computing.net]
> > Sent: 12 July 2000 23:10
> > To: PHP General
> > Subject: [PHP] Encryption
> >
> >
> > Up until now I've always used md5() or the mysql password()
> > functions to
> > store passwords. However, I'm now faced with the dilemma of having the
> > facility to retreive these passwords if forgotten. So I
> > presumably have
> > to use some form of key'ed encryption...? Is there a way to do it with
> > php/MySQL?
> >
Your pretty much stuck. MD5 is a one way encryption. If its in
your database MD5 encrypted you cant unencrypt it, so you wont
be able to send them their password in human readable form.
In my user/password databases I use an additional field called
password hint and have the user set a hint word or phrase.
When they lose their password you send the hint. If the hint isnt
good enough to remind them and passwords are MD5 encrypted the only
answer is to set it to another MD5 encrypted string that you know and
send it to the user as their new password. Then give them a chance to
change it and provide a hint....and so on and so on and so on
Hope this helps
Dan Krumlauf