note 27656 rejected from function.md5 by betz
| From: | betz@php.net | Date: | Sat, 14 Dec 2002 15:53:55 +0000 |
| Subject: | note 27656 rejected from function.md5 by betz | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-40905@lists.php.net to get a copy of this message | ||
I am having trouble understand this whole encryption thing with md5. I have figured out how to
create a public and secret key for rsa take a digit and encrypt it. But I can't find out how
to use md5. Does md5 encrypt? If I have a site where I don't want to bother with ssl and I
want to authenticate users by passwords stored in a database how would I use md5 to securly encrypt
the password send it in a post and then unencrypt it in my php code and see if they match. BTW I
have a javascript md5 script that will do the encryption client side at http://pajhome.org.uk/crypt/md5/index.html
My biggest concern is that the encrypted password for the users will always be the same. So if bob
has a password of password, the md5 will always be the same everytime he logs in. Thus all a hacker
will need to do is capture the password in its encrypted form and then pass it on someother time
when he wants in. Or am I totally wrong and the md5 is different every time?
Thank you for your help