note 26022 deleted from function.md5 by jimw

From: Date: Sat, 08 Feb 2003 19:50:21 +0000
Subject: note 26022 deleted from function.md5 by jimw
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-43647@lists.php.net to get a copy of this message
This is to everyone who said "just store the md5 hash of the users password on the server, then get the user to send the the hash of their password to log in." This technique is just as bad as sending a clear text password, if an attacker was to intercept the user sending the hash of their password, then all they would need to do is submit the same hash to gain access. Always use some kind of random variable.

« previous php.notes (#43647) next »