RE: Secure registration and log in script - Part 2 of 2 - The Log In 11-13-2013, 10:39 AM
#11
(11-13-2013, 10:09 AM)shp0ngl3 Wrote: I give up.. Seriously, I give up! First you provide a function that uses sha1 and md5 x 3 times or something (Yes I'm going back to the IRC chat now).. Both me and @1llusion tells you that it is NOT secure, and you keep arguing that you're method is secure because you use it more than one time and have salts! Then @Anima Templi tries to help you but you refuse to listen to his suggestion. On top of this you admit that you are new to PHP, and still you have the balls to tell me that after my 13 years of experience I still have no clue what I'm talking about.. Consider this my last time helping you out.
Why is it more secure you ask?
- When done properly you need two attacks to get to the key. You can even store it on a separate server if you want. So by using the key file you will have to break into the actual server not just dump it with a simple sql injection
- On top of the HMAC you have a blowfish hash which uses a unique salt for each hash that you do not need to store. The algorithm handles this on its own.Code:concat_ws(0x3a,username,password,salt)
- The key stored has a much stronger cryptographic entropy than your average salt stored in a database. I mean, this doesn't provide good entropy
MyBB's salt generator:
Code:function random_str($length="8") { $set = array("a","A","b","B","c","C","d","D","e","E","f","F","g","G","h","H","i","I","j","J","k","K","l","L","m","M","n","N","o","O","p","P","q","Q","r","R","s","S","t","T","u","U","v","V","w","W","x","X","y","Y","z","Z","1","2","3","4","5","6","7","8","9"); $str = ''; for($i = 1; $i <= $length; ++$i) { $ch = my_rand(0, count($set)-1); $str .= $set[$ch]; } return $str; }
I will leave you with a blog post from Mozilla security team about how to store passwords securely, and you will see that the method used is the one described here.
http://blog.mozilla.org/webdev/2012/06/0...d-storage/
well that explained it prety much thanks for the information.





![[Image: 120x240.gif]](http://www.gomezpeerzone.com/wp-content/uploads/2011/11/120x240.gif)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)