Re: User Authentication
| From: | Jason G. | Date: | Mon, 08 Oct 2001 04:26:26 +0000 |
| Subject: | Re: User Authentication | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-70316@lists.php.net to get a copy of this message | ||
Use https as previously mentioned.
When storing passwords in the db, use md5 to store them, and then md5 the user entered password, and compare it with the md5's in the db. On the downside, you can never, I repeat, NEVER tell what a user's password is by the md5.
-Jason Garber
IonZoft.com
At 08:05 PM 10/7/2001 -0400, Tom Malone wrote:
Hello I am writing a web mail application (attempting to, anyway) and am wondering -- what is the best way to protect users' passwords that are communicated to PHP when the user logs in? JavaScript can't encrypt it, and of course it won't do me much good to encrypt it in my PHP script after it gets to the server. If I use the crypt() or md5() function to make it into a hash when it gets there, and then compare it to a hash of the original password that's stored in a password-protected database, would that be relatively secure? Someone could intercept the password on its way to the server, but they wouldn't know if it was the correct one, am I right? If anyone has a better solution, I would be most grateful. Thank you. Tom Malone Web Designer http://www.tom-malone.com -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net