note 18466 added to function.crypt
| From: | anonymous at php2 dot chek dot com | Date: | Thu, 24 Jan 2002 05:32:09 +0000 |
| Subject: | note 18466 added to function.crypt | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-25769@lists.php.net to get a copy of this message | ||
Note that md5crypt and md5 are NOT the same. md5crypt is salted to prevent "birthday
attacks", and goes through many iterations to make it expensive to attack. (Don't be
alarmed, it's only expensive if you're brute-forcing or dictionary attacking it,
human-typed passwords won't cause load on your web server).
The salting is a *must*, otherwise 2 people picking the same password will have the same hash
(saving an attacker a lot of time!).
IMHO, crypt() should use the DES-based crypt, and md5crypt() and bfcrypt() should be in separate
functions. (the PHP 4.0.4 -> 4.1.1 upgrade broke some of the sites on my webserver due to this
sillyness!)
--
http://www.php.net/manual/en/function.crypt.php
http://master.php.net/manage/user-notes.php?action=edit+18466
http://master.php.net/manage/user-notes.php?action=delete+18466
http://master.php.net/manage/user-notes.php?action=reject+18466