Sinisterly
Tutorial [MyBB] Improved password encryption. - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: PHP (https://sinister.li/Forum-PHP)
+--- Thread: Tutorial [MyBB] Improved password encryption. (/Thread-Tutorial-MyBB-Improved-password-encryption)

Pages: 1 2 3 4 5 6 7


RE: [MyBB] Improved password encryption. - The Protagonist - 01-03-2015

Adding in a sha1 won't make all that much difference. Bcrypt as w00t said is clearly the way to go.
He suggested bcrypting the whole thing like
bcrypt(md5($salt) . md5($password))
But you could also just catch everyone on next login and bcrypt their password.


RE: [MyBB] Improved password encryption. - Lain - 01-04-2015

(01-03-2015, 05:55 PM)phyrrus9 Wrote: How about we just get rid of md5 in it altogether in password hashing...

PHP Code:
function generate_hash($password, $salt) { return md5(sha1(md5($salt) . md5($password))); }

That won't be getting broken anytime soon.

Wow necropost, reported.

And yeah, this tutorial was pretty shit.


RE: [MyBB] Improved password encryption. - Eclipse - 01-04-2015

(01-04-2015, 12:48 AM)Senpai Wrote: Wow necropost, reported.

And yeah, this tutorial was pretty shit.

Doesn't really count as gravedigging if the post is actually something useful.


RE: [MyBB] Improved password encryption. - Lain - 01-04-2015

(01-04-2015, 12:55 AM)Eclipse Wrote: Doesn't really count as gravedigging if the post is actually something useful.

Shh, it was a joke, settle down.


RE: [MyBB] Improved password encryption. - Eclipse - 01-04-2015

(01-04-2015, 12:56 AM)Senpai Wrote: Shh, it was a joke, settle down.

How was your first time with a jew?

OT: It's hard to judge emotion over the internet. Shh.

Seriously OT: This looks like it'd take a while, and yes, a better encryption algorithm would be preferable.


RE: [MyBB] Improved password encryption. - phyrrus9 - 01-04-2015

(01-04-2015, 12:59 AM)Eclipse Wrote: How was your first time with a jew?

Actually, it was pretty amazing Tongue

Quote:OT: It's hard to judge emotion over the internet. Shh.

Seriously OT: This looks like it'd take a while, and yes, a better encryption algorithm would be preferable.

Yeah, if we implemented something good, we wouldn't have to worry about DB leaks as much. I recommended it


RE: [MyBB] Improved password encryption. - lux - 01-04-2015

Or you could over complicate shit and parse in the userID and times that by pi, then concat it to the string pre-hash.


RE: [MyBB] Improved password encryption. - Kizaru - 01-04-2015

(01-04-2015, 03:06 AM)phyrrus9 Wrote: Actually, it was pretty amazing Tongue


Yeah, if we implemented something good, we wouldn't have to worry about DB leaks as much. I recommended it

I recommend looking into this then
https://github.com/TacticalCode/MyBBcrypt/blob/26918b2a37c9013eaa43abb1ea57663e21dc1138/inc/functions_user.php

It implements bcrypt into mybb.


RE: [MyBB] Improved password encryption. - phyrrus9 - 01-04-2015

Looks REALLY simple... I should write a RSA version Tongue

Maybe RSA encrypt the entire database, so every time you query something it has to RSA decrypt it for validation or something. Hmm, neat.


RE: [MyBB] Improved password encryption. - warstrike - 01-04-2015

use sha384+salt or bcrypt+salt.