note 20855 added to function.md5
| From: | spam at pbbt dot com | Date: | Thu, 18 Apr 2002 19:04:24 +0000 |
| Subject: | note 20855 added to function.md5 | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-29535@lists.php.net to get a copy of this message | ||
In regard to the comment by mogster@boomdesign.no:
If you md5 a password and submit that in a form over an unencrypted link instead of submitting the
plain password, then all the hacker needs to do is steal the md5 code to log in. It doesn't
really increase security very much, except that it's harder to brute-force guess the password.
The best way to go is to use a SSL page... it's secure, fairly easy, and will work fine with
your existing code.
Owen
--
http://www.php.net/manual/en/function.md5.php
http://master.php.net/manage/user-notes.php?action=edit+20855
http://master.php.net/manage/user-notes.php?action=delete+20855
http://master.php.net/manage/user-notes.php?action=reject+20855