note 70890 added to security.database.storage

From: Date: Fri, 03 Nov 2006 00:05:35 +0000
Subject: note 70890 added to security.database.storage
Groups: php.notes 
Request: Send a blank email to php-notes+get-119327@lists.php.net to get a copy of this message
You should always hash the password with the username, so store md5($password . $username) instead of md5($password) This way the cracker cannot use a precomputed set of hashes of common keys, but has to recompute the hashes for each user. Double hashing also can help in some situations as it solves length extension problems with all hash functions. Also you should use SHA-256, as it has a longer hash length and thus it takes 2^128 steps to find a collision ---- Server IP: 66.163.161.117 Probable Submitter: 82.3.32.72 (proxied: 86.2.100.5) ---- Manual Page -- http://www.php.net/manual/en/security.database.storage.php Edit -- https://master.php.net/note/edit/70890 Del: integrated -- https://master.php.net/note/delete/70890/integrated Del: useless -- https://master.php.net/note/delete/70890/useless Del: bad code -- https://master.php.net/note/delete/70890/bad+code Del: spam -- https://master.php.net/note/delete/70890/spam Del: non-english -- https://master.php.net/note/delete/70890/non-english Del: in docs -- https://master.php.net/note/delete/70890/in+docs Del: other reasons-- https://master.php.net/note/delete/70890 Reject -- https://master.php.net/note/reject/70890 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#119327) next »