Sinisterly
How to hash password correctly in PHP? - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: PHP (https://sinister.li/Forum-PHP)
+--- Thread: How to hash password correctly in PHP? (/Thread-How-to-hash-password-correctly-in-PHP)

Pages: 1 2 3


RE: How to hash password correctly in PHP? - Jakub - 08-25-2017

(08-25-2017, 09:53 PM)Sikom Wrote:
(08-25-2017, 09:51 PM)Jakub Wrote: Im hashing passwords on my websites/scripts using double md5 + salt and i personally prefer this way.

md5 is not really secure though is it?

i'm working with it for 1 year now and for now it's okay. But i have my own "hash" function so if double md5 with salt fails i will switch to my hash function


RE: How to hash password correctly in PHP? - Sikom - 08-25-2017

(08-25-2017, 10:00 PM)Jakub Wrote:
(08-25-2017, 09:53 PM)Sikom Wrote:
(08-25-2017, 09:51 PM)Jakub Wrote: Im hashing passwords on my websites/scripts using double md5 + salt and i personally prefer this way.

md5 is not really secure though is it?

i'm working with it for 1 year now and for now it's okay. But i have my own "hash" function so if double md5 with salt fails i will switch to my hash function

What do you mean by your own "hash" function? I think MD5 is considered unsecure, and I don't think you should use it.


RE: How to hash password correctly in PHP? - Jakub - 08-25-2017

I have my own algorythm, php script which is hashing passwords, texts etc. (i.e. it will change "a" to "#72gwvs&") i'm using that hashing for my own private website where i have all of my projects. Once a month i'm changing algorythm for safety


RE: How to hash password correctly in PHP? - Sikom - 08-25-2017

(08-25-2017, 10:19 PM)Jakub Wrote: I have my own algorythm, php script which is hashing passwords, texts etc. (i.e. it will change "a" to "#72gwvs&") i'm using that hashing for my own private website where i have all of my projects. Once a month i'm changing algorythm for safety

Do you even know anything about cryptology?


RE: How to hash password correctly in PHP? - Blink - 08-25-2017

(08-25-2017, 10:00 PM)Jakub Wrote:
(08-25-2017, 09:53 PM)Sikom Wrote:
(08-25-2017, 09:51 PM)Jakub Wrote: Im hashing passwords on my websites/scripts using double md5 + salt and i personally prefer this way.

md5 is not really secure though is it?

i'm working with it for 1 year now and for now it's okay. But i have my own "hash" function so if double md5 with salt fails i will switch to my hash function

This beyond stupid.
MD5 was peer reviewed and looked over by tons of security experts, yet it was still broken.
Your own algorithm is probably not as advanced as MD5, and is a major security hole.

Use bcrypt or something ffs

PHP has a password_hash() function for a reason. Use it, the default algorithm is BCRYPT. @Sikom this goes to you aswell.


RE: How to hash password correctly in PHP? - Ecks - 08-26-2017

Never try to out think crackers man, never use your own algorithm, always use opensourced crypto.


RE: How to hash password correctly in PHP? - mothered - 08-26-2017

(08-25-2017, 11:54 PM)Ender Wrote: PHP has a password_hash() function for a reason.  Use it, the default algorithm is BCRYPT.

This ^^ Enough said.

It's key stretching algorithm speaks for Itself.


RE: How to hash password correctly in PHP? - Sikom - 08-26-2017

(08-25-2017, 11:54 PM)Ender Wrote:
(08-25-2017, 10:00 PM)Jakub Wrote:
(08-25-2017, 09:53 PM)Sikom Wrote: md5 is not really secure though is it?

i'm working with it for 1 year now and for now it's okay. But i have my own "hash" function so if double md5 with salt fails i will switch to my hash function

This beyond stupid.
MD5 was peer reviewed and looked over by tons of security experts, yet it was still broken.
Your own algorithm is probably not as advanced as MD5, and is a major security hole.

Use bcrypt or something ffs

Would agree with that being beyond stupid


Is this a good solution @'ender'?
Code:
function hashPassword($password, $salt){    $secretkey = 'A long key that is in code. Over 1000 chars';        //Amount of iterations    $iterations = 100;    $hash = hash('sha512', $salt . $password . $secretkey);    for($i = 0; i < $iterations-1; $i++) {        $hash = hash('sha512', $salt . $hash . $secretkey);    }    return $hash; } function checkPassword($password, $hashedPassword, $salt){    //Hashes the password for comparing to the hashedPassword in the db    $hash = hashPassword($password, $salt);    //Sleep to prevent a timing attack    usleep(random_int(100,1000));    if($hash === $hashedPassword){        return true;    }    return false; }



RE: How to hash password correctly in PHP? - Pikami - 08-26-2017

(08-26-2017, 11:15 AM)Sikom Wrote:
(08-25-2017, 11:54 PM)Ender Wrote:
(08-25-2017, 10:00 PM)Jakub Wrote: i'm working with it for 1 year now and for now it's okay. But i have my own "hash" function so if double md5 with salt fails i will switch to my hash function

This beyond stupid.
MD5 was peer reviewed and looked over by tons of security experts, yet it was still broken.
Your own algorithm is probably not as advanced as MD5, and is a major security hole.

Use bcrypt or something ffs

Would agree with that being beyond stupid


Is this a good solution @'ender'?
Code:
function hashPassword($password, $salt){    $secretkey = 'A long key that is in code. Over 1000 chars';        //Amount of iterations    $iterations = 100;    $hash = hash('sha512', $salt . $password . $secretkey);    for($i = 0; i < $iterations-1; $i++) {        $hash = hash('sha512', $salt . $hash . $secretkey);    }    return $hash; } function checkPassword($password, $hashedPassword, $salt){    //Hashes the password for comparing to the hashedPassword in the db    $hash = hashPassword($password, $salt);    //Sleep to prevent a timing attack    usleep(random_int(100,1000));    if($hash === $hashedPassword){        return true;    }    return false; }

This is not a good solution.
Use BCRYPT man


RE: How to hash password correctly in PHP? - Sikom - 08-26-2017

(08-26-2017, 12:48 PM)Pikami Wrote:
(08-26-2017, 11:15 AM)Sikom Wrote:
(08-25-2017, 11:54 PM)Ender Wrote: This beyond stupid.
MD5 was peer reviewed and looked over by tons of security experts, yet it was still broken.
Your own algorithm is probably not as advanced as MD5, and is a major security hole.

Use bcrypt or something ffs

Would agree with that being beyond stupid


Is this a good solution @'ender'?
Code:
function hashPassword($password, $salt){    $secretkey = 'A long key that is in code. Over 1000 chars';        //Amount of iterations    $iterations = 100;    $hash = hash('sha512', $salt . $password . $secretkey);    for($i = 0; i < $iterations-1; $i++) {        $hash = hash('sha512', $salt . $hash . $secretkey);    }    return $hash; } function checkPassword($password, $hashedPassword, $salt){    //Hashes the password for comparing to the hashedPassword in the db    $hash = hashPassword($password, $salt);    //Sleep to prevent a timing attack    usleep(random_int(100,1000));    if($hash === $hashedPassword){        return true;    }    return false; }

This is not a good solution.
Use BCRYPT man

Why is that not a good solution?