User Authentication

From: Date: Mon, 08 Oct 2001 00:05:10 +0000
Subject: User Authentication
Groups: php.general 
Request: Send a blank email to php-general+get-70307@lists.php.net to get a copy of this message
Hello I am writing a web mail application (attempting to, anyway) and am wondering -- what is the best way to protect users' passwords that are communicated to PHP when the user logs in? JavaScript can't encrypt it, and of course it won't do me much good to encrypt it in my PHP script after it gets to the server. If I use the crypt() or md5() function to make it into a hash when it gets there, and then compare it to a hash of the original password that's stored in a password-protected database, would that be relatively secure? Someone could intercept the password on its way to the server, but they wouldn't know if it was the correct one, am I right? If anyone has a better solution, I would be most grateful. Thank you. Tom Malone Web Designer http://www.tom-malone.com

« previous php.general (#70307) next »