note 30525 deleted from function.crypt by aidan

From: Date: Mon, 05 Jul 2004 10:28:21 +0000
Subject: note 30525 deleted from function.crypt by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-72587@lists.php.net to get a copy of this message
Note Submitter: anj@aps.anl.gov ---- To generate your own 2-character DES encryption salt from the current time, use something like this code: $cset = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789./"; $salt = substr($cset, time() & 63, 1) . substr($cset, time()/64 & 63, 1); $encrypted = crypt($password, $salt); The salt is there to ensure that if two users happen to pick the same password, the result (usually) encrypts to a different string so it's not obvious to someone looking through the password file if that happens. It also makes it harder to crack passwords because it means there are 4096 different encryption algorithms, but since the first two characters of $encrypted give the salt it's not essential that it be random, just that it varies. However it is *not* a good idea to use the first two characters of the user's password as the salt as some previous commenters have said. The salt characters must be from the limited character set shown above [a-zA-Z0-9./] which the password characters might not be, and you're also significantly reducing the strength of your system's security by giving out the first 2 characters of your users' passwords to anyone who manages to read the password file somehow.

« previous php.notes (#72587) next »