note 22649 modified in function.crypt by vrana
| From: | vrana@php.net | Date: | Tue, 17 Aug 2004 14:56:00 +0000 |
| Subject: | note 22649 modified in function.crypt by vrana | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-80031@lists.php.net to get a copy of this message | ||
There's always been a bit of confusion as to what makes a good salt and what doesn't.
Remember that it doesn't matter at all how easy a salt is to guess. No one ever HAS to guess
the salt: it's already given.
The only only important consideration when generating a salt is to make sure that all salts are
unique--that way the same password will be encrypted differently (i.e. the encrypted passwords will
look different) for different users.
One of the simplest ways to generate a unique salt is to use some string that will be different
every time the procedure is called. Here's a simple example:
<?php
$jumble = md5(time() . getmypid());
$salt = substr($jumble,0,$salt_length);
?>
Given a string consisting of the current time (in seconds) concatinated with the current process id,
the string will never be the same twice, assuming that the function is never called more than once
per second. Calculating the md5 sum over that string creates another string from which you can
extract any substring and still end up with a unique sequence.
If you're going to be generating more than one password per second, just throw a rand($x,$y) in
there to add a little more entropy.
--was--
There's always been a bit of confusion as to what makes a good salt and what doesn't.
Remember that it doesn't matter at all how easy a salt is to guess. No one ever HAS to guess
the salt: it's already given.
The only only important consideration when generating a salt is to make sure that all salts are
unique--that way the same password will be encrypted differently (i.e. the encrypted passwords will
look different) for different users.
One of the simplest ways to generate a unique salt is to use some string that will be different
every time the procedure is called. Here's a simple example:
$jumble = md5(time() . getmypid());
$salt = substr($jumble,0,$salt_length);
Given a string consisting of the current time (in seconds) concatinated with the current process id,
the string will never be the same twice, assuming that the function is never called more than once
per second. Calculating the md5 sum over that string creates another string from which you can
extract any substring and still end up with a unique sequence.
If you're going to be generating more than one password per second, just throw a rand($x,$y) in
there to add a little more entropy.
http://php.net/manual/en/function.crypt.php