note 30525 deleted from function.crypt by aidan
| From: | aidan@php.net | Date: | Mon, 05 Jul 2004 10:28:21 +0000 |
| Subject: | note 30525 deleted from function.crypt by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-72587@lists.php.net to get a copy of this message | ||
Note Submitter: anj@aps.anl.gov
----
To generate your own 2-character DES encryption salt from the current time, use something like this
code:
$cset = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789./";
$salt = substr($cset, time() & 63, 1) .
substr($cset, time()/64 & 63, 1);
$encrypted = crypt($password, $salt);
The salt is there to ensure that if two users happen to pick the same password, the result (usually)
encrypts to a different string so it's not obvious to someone looking through the password file
if that happens. It also makes it harder to crack passwords because it means there are 4096
different encryption algorithms, but since the first two characters of $encrypted give the salt
it's not essential that it be random, just that it varies.
However it is *not* a good idea to use the first two characters of the user's password as the
salt as some previous commenters have said. The salt characters must be from the limited character
set shown above [a-zA-Z0-9./] which the password characters might not be, and you're also
significantly reducing the strength of your system's security by giving out the first 2
characters of your users' passwords to anyone who manages to read the password file somehow.