note 22649 modified in function.crypt by vrana

From: Date: Tue, 17 Aug 2004 14:56:00 +0000
Subject: note 22649 modified in function.crypt by vrana
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-80031@lists.php.net to get a copy of this message
There's always been a bit of confusion as to what makes a good salt and what doesn't. Remember that it doesn't matter at all how easy a salt is to guess. No one ever HAS to guess the salt: it's already given. The only only important consideration when generating a salt is to make sure that all salts are unique--that way the same password will be encrypted differently (i.e. the encrypted passwords will look different) for different users. One of the simplest ways to generate a unique salt is to use some string that will be different every time the procedure is called. Here's a simple example: <?php $jumble = md5(time() . getmypid()); $salt = substr($jumble,0,$salt_length); ?> Given a string consisting of the current time (in seconds) concatinated with the current process id, the string will never be the same twice, assuming that the function is never called more than once per second. Calculating the md5 sum over that string creates another string from which you can extract any substring and still end up with a unique sequence. If you're going to be generating more than one password per second, just throw a rand($x,$y) in there to add a little more entropy. --was-- There's always been a bit of confusion as to what makes a good salt and what doesn't. Remember that it doesn't matter at all how easy a salt is to guess. No one ever HAS to guess the salt: it's already given. The only only important consideration when generating a salt is to make sure that all salts are unique--that way the same password will be encrypted differently (i.e. the encrypted passwords will look different) for different users. One of the simplest ways to generate a unique salt is to use some string that will be different every time the procedure is called. Here's a simple example: $jumble = md5(time() . getmypid()); $salt = substr($jumble,0,$salt_length); Given a string consisting of the current time (in seconds) concatinated with the current process id, the string will never be the same twice, assuming that the function is never called more than once per second. Calculating the md5 sum over that string creates another string from which you can extract any substring and still end up with a unique sequence. If you're going to be generating more than one password per second, just throw a rand($x,$y) in there to add a little more entropy. http://php.net/manual/en/function.crypt.php

« previous php.notes (#80031) next »