note 22649 deleted from function.crypt by joey

From: Date: Mon, 27 Dec 2010 12:21:08 +0000
Subject: note 22649 deleted from function.crypt by joey
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-175233@lists.php.net to get a copy of this message
Note Submitter: php at SPAM_tlarson dot com ---- There's always been a bit of confusion as to what makes a good salt and what doesn't. Remember that it doesn't matter at all how easy a salt is to guess. No one ever HAS to guess the salt: it's already given. The only only important consideration when generating a salt is to make sure that all salts are unique--that way the same password will be encrypted differently (i.e. the encrypted passwords will look different) for different users. One of the simplest ways to generate a unique salt is to use some string that will be different every time the procedure is called. Here's a simple example: <?php $jumble = md5(time() . getmypid()); $salt = substr($jumble,0,$salt_length); ?> Given a string consisting of the current time (in seconds) concatinated with the current process id, the string will never be the same twice, assuming that the function is never called more than once per second. Calculating the md5 sum over that string creates another string from which you can extract any substring and still end up with a unique sequence. If you're going to be generating more than one password per second, just throw a rand($x,$y) in there to add a little more entropy.

« previous php.notes (#175233) next »