note 39922 deleted from function.setcookie by tularis
| From: | tularis@php.net | Date: | Sun, 02 Jan 2005 14:18:25 +0000 |
| Subject: | note 39922 deleted from function.setcookie by tularis | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-82581@lists.php.net to get a copy of this message | ||
Note Submitter:
----
The note by: "apex at xepa dot nl" on 24-Nov-2003 06:59
"Another note on storing passwords .. don't use MD5 it's too weak."
I believe that your statement is a little off there, MD5 is not an encryption. It is a hash and is
by far the hardest hash to crack. The reason you're probably saying that it's too weak is
because chances are you are using regular words as passwords[Example: banana]. Thus: It's a
snap to crack with a quick script. If you add in a script to force the user to have a certain length
of characters and must contain a certain amount of numbers, you would be fine. MD5 is very widely
available, and most people do not have access to change their PHP settings and add in modules.