note 26022 deleted from function.md5 by jimw
| From: | jimw@php.net | Date: | Sat, 08 Feb 2003 19:50:21 +0000 |
| Subject: | note 26022 deleted from function.md5 by jimw | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-43647@lists.php.net to get a copy of this message | ||
This is to everyone who said "just store the md5 hash of the users password on the server, then
get the user to send the the hash of their password to log in."
This technique is just as bad as sending a clear text password, if an attacker was to intercept the
user sending the hash of their password, then all they would need to do is submit the same hash to
gain access.
Always use some kind of random variable.