note 70890 deleted from security.database.storage by joey

From: Date: Wed, 28 Dec 2011 08:42:32 +0000
Subject: note 70890 deleted from security.database.storage by joey
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-185262@lists.php.net to get a copy of this message
Note Submitter: Ketos ---- You should always hash the password with the username, so store md5($password . $username) instead of md5($password) This way the cracker cannot use a precomputed set of hashes of common keys, but has to recompute the hashes for each user. Double hashing also can help in some situations as it solves length extension problems with all hash functions. Also you should use SHA-256, as it has a longer hash length and thus it takes 2^128 steps to find a collision

« previous php.notes (#185262) next »