Re: User Authentication

From: Date: Mon, 08 Oct 2001 00:14:38 +0000
Subject: Re: User Authentication
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-70308@lists.php.net to get a copy of this message
At 08:05 PM 10/7/2001, Tom Malone wrote: use https for anything that you want secure....trust me - true - the password may not be the right one...but the next one will be :-) ~kurth
Hello I am writing a web mail application (attempting to, anyway) and am wondering -- what is the best way to protect users' passwords that are communicated to PHP when the user logs in? JavaScript can't encrypt it, and of course it won't do me much good to encrypt it in my PHP script after it gets to the server. If I use the crypt() or md5() function to make it into a hash when it gets there, and then compare it to a hash of the original password that's stored in a password-protected database, would that be relatively secure? Someone could intercept the password on its way to the server, but they wouldn't know if it was the correct one, am I right? If anyone has a better solution, I would be most grateful. Thank you. Tom Malone Web Designer http://www.tom-malone.com -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net


« previous php.general (#70308) next »