Login Register






Tutorial [MyBB] Improved password encryption. filter_list
Author
Message
RE: [MyBB] Improved password encryption. #21
Adding in a sha1 won't make all that much difference. Bcrypt as w00t said is clearly the way to go.
He suggested bcrypting the whole thing like
bcrypt(md5($salt) . md5($password))
But you could also just catch everyone on next login and bcrypt their password.

Reply

RE: [MyBB] Improved password encryption. #22
(01-03-2015, 05:55 PM)phyrrus9 Wrote: How about we just get rid of md5 in it altogether in password hashing...

PHP Code:
function generate_hash($password, $salt) { return md5(sha1(md5($salt) . md5($password))); }

That won't be getting broken anytime soon.

Wow necropost, reported.

And yeah, this tutorial was pretty shit.

Reply

RE: [MyBB] Improved password encryption. #23
(01-04-2015, 12:48 AM)Senpai Wrote: Wow necropost, reported.

And yeah, this tutorial was pretty shit.

Doesn't really count as gravedigging if the post is actually something useful.

Reply

RE: [MyBB] Improved password encryption. #24
(01-04-2015, 12:55 AM)Eclipse Wrote: Doesn't really count as gravedigging if the post is actually something useful.

Shh, it was a joke, settle down.

Reply

RE: [MyBB] Improved password encryption. #25
(01-04-2015, 12:56 AM)Senpai Wrote: Shh, it was a joke, settle down.

How was your first time with a jew?

OT: It's hard to judge emotion over the internet. Shh.

Seriously OT: This looks like it'd take a while, and yes, a better encryption algorithm would be preferable.

Reply

RE: [MyBB] Improved password encryption. #26
(01-04-2015, 12:59 AM)Eclipse Wrote: How was your first time with a jew?

Actually, it was pretty amazing Tongue

Quote:OT: It's hard to judge emotion over the internet. Shh.

Seriously OT: This looks like it'd take a while, and yes, a better encryption algorithm would be preferable.

Yeah, if we implemented something good, we wouldn't have to worry about DB leaks as much. I recommended it

Reply

RE: [MyBB] Improved password encryption. #27
Or you could over complicate shit and parse in the userID and times that by pi, then concat it to the string pre-hash.

Reply

RE: [MyBB] Improved password encryption. #28
(01-04-2015, 03:06 AM)phyrrus9 Wrote: Actually, it was pretty amazing Tongue


Yeah, if we implemented something good, we wouldn't have to worry about DB leaks as much. I recommended it

I recommend looking into this then
https://github.com/TacticalCode/MyBBcryp...s_user.php

It implements bcrypt into mybb.

Reply

RE: [MyBB] Improved password encryption. #29
Looks REALLY simple... I should write a RSA version Tongue

Maybe RSA encrypt the entire database, so every time you query something it has to RSA decrypt it for validation or something. Hmm, neat.

Reply

RE: [MyBB] Improved password encryption. #30
use sha384+salt or bcrypt+salt.

Reply