note 27692 deleted from function.crypt by nlopess
| From: | nlopess@php.net | Date: | Sat, 03 Jan 2004 16:39:15 +0000 |
| Subject: | note 27692 deleted from function.crypt by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-62869@lists.php.net to get a copy of this message | ||
Note Submitter: WebMaster[AT]ReikiMagazine[DOT]com
----
How about using the first two characters of the USERNAME as a salt? This will prevent the problem
with equal first eight characters in passwords in most cases, and will also not leave the first two
characters of the plain-text password open in .htaccess files.