Re: Encryption

From: Date: Thu, 13 Jul 2000 00:09:38 +0000
Subject: Re: Encryption
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-6341@lists.php.net to get a copy of this message
Richard Heyes wrote: > > Oops. Just found the encryption section of the manual... > > But I still have to store the key in the script though yes? Can't be > very secure. > > -- > Richard Heyes > http://www.heyes-computing.net/scripts/ > Plain text email only please! > > > -----Original Message----- > > From: Richard Heyes [mailto:php@heyes-computing.net] > > Sent: 12 July 2000 23:10 > > To: PHP General > > Subject: [PHP] Encryption > > > > > > Up until now I've always used md5() or the mysql password() > > functions to > > store passwords. However, I'm now faced with the dilemma of having the > > facility to retreive these passwords if forgotten. So I > > presumably have > > to use some form of key'ed encryption...? Is there a way to do it with > > php/MySQL? > > Your pretty much stuck. MD5 is a one way encryption. If its in your database MD5 encrypted you cant unencrypt it, so you wont be able to send them their password in human readable form. In my user/password databases I use an additional field called password hint and have the user set a hint word or phrase. When they lose their password you send the hint. If the hint isnt good enough to remind them and passwords are MD5 encrypted the only answer is to set it to another MD5 encrypted string that you know and send it to the user as their new password. Then give them a chance to change it and provide a hint....and so on and so on and so on Hope this helps Dan Krumlauf

« previous php.general (#6341) next »