User Authentication
| From: | Tom Malone | Date: | Mon, 08 Oct 2001 00:05:10 +0000 |
| Subject: | User Authentication | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-70307@lists.php.net to get a copy of this message | ||
Hello
I am writing a web mail application (attempting to, anyway) and am
wondering -- what is the best way to protect users' passwords that are
communicated to PHP when the user logs in? JavaScript can't encrypt it, and
of course it won't do me much good to encrypt it in my PHP script after it
gets to the server. If I use the crypt() or md5() function to make it into a
hash when it gets there, and then compare it to a hash of the original
password that's stored in a password-protected database, would that be
relatively secure? Someone could intercept the password on its way to the
server, but they wouldn't know if it was the correct one, am I right? If
anyone has a better solution, I would be most grateful. Thank you.
Tom Malone
Web Designer
http://www.tom-malone.com