Re: [DRAFT RFC] Adding Simplified Password Hashing API
| From: | Anthony Ferrara | Date: | Thu, 28 Jun 2012 01:52:49 +0000 |
| Subject: | Re: [DRAFT RFC] Adding Simplified Password Hashing API | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-61010@lists.php.net to get a copy of this message | ||
Arvids,
On Wed, Jun 27, 2012 at 12:32 PM, Arvids Godjuks
<arvids.godjuks@gmail.com> wrote:
> On that note I have only one request - please point me to the good article
> that describes how this thing works (I would prefer one that at least tries
> to explain in simple words) because at the moment i do not understand how
> salt stored in the hash itself makes hash more secure than an unsalted one.
Here are some articles that are worth while:
http://php.net/manual/en/function.crypt.php
http://www.devshed.com/c/a/PHP/Using-the-PHP-Crypt-Function/
http://stackoverflow.com/a/4808616/338665
If more explanation is needed, I can try to expand the RFC a bit more.
But give the new sections a read and let me know what you think.
Thanks,
Anthony