note 70890 added to security.database.storage
| From: | Ketos at osu1 dot php dot net | Date: | Fri, 03 Nov 2006 00:05:35 +0000 |
| Subject: | note 70890 added to security.database.storage | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-119327@lists.php.net to get a copy of this message | ||
You should always hash the password with the username, so store md5($password . $username) instead
of md5($password) This way the cracker cannot use a precomputed set of hashes of common keys, but
has to recompute the hashes for each user.
Double hashing also can help in some situations as it solves length extension problems with all hash
functions. Also you should use SHA-256, as it has a longer hash length and thus it takes 2^128 steps
to find a collision
----
Server IP: 66.163.161.117
Probable Submitter: 82.3.32.72 (proxied: 86.2.100.5)
----
Manual Page -- http://www.php.net/manual/en/security.database.storage.php
Edit -- https://master.php.net/note/edit/70890
Del: integrated -- https://master.php.net/note/delete/70890/integrated
Del: useless -- https://master.php.net/note/delete/70890/useless
Del: bad code -- https://master.php.net/note/delete/70890/bad+code
Del: spam -- https://master.php.net/note/delete/70890/spam
Del: non-english -- https://master.php.net/note/delete/70890/non-english
Del: in docs -- https://master.php.net/note/delete/70890/in+docs
Del: other reasons-- https://master.php.net/note/delete/70890
Reject -- https://master.php.net/note/reject/70890
Search -- https://master.php.net/manage/user-notes.php