![]() |
|
Tutorial [MyBB] Improved password encryption. - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: PHP (https://sinister.li/Forum-PHP) +--- Thread: Tutorial [MyBB] Improved password encryption. (/Thread-Tutorial-MyBB-Improved-password-encryption) |
RE: [MyBB] Improved password encryption. - The Protagonist - 01-03-2015 Adding in a sha1 won't make all that much difference. Bcrypt as w00t said is clearly the way to go. He suggested bcrypting the whole thing like bcrypt(md5($salt) . md5($password)) But you could also just catch everyone on next login and bcrypt their password. RE: [MyBB] Improved password encryption. - Lain - 01-04-2015 (01-03-2015, 05:55 PM)phyrrus9 Wrote: How about we just get rid of md5 in it altogether in password hashing... Wow necropost, reported. And yeah, this tutorial was pretty shit. RE: [MyBB] Improved password encryption. - Eclipse - 01-04-2015 (01-04-2015, 12:48 AM)Senpai Wrote: Wow necropost, reported. Doesn't really count as gravedigging if the post is actually something useful. RE: [MyBB] Improved password encryption. - Lain - 01-04-2015 (01-04-2015, 12:55 AM)Eclipse Wrote: Doesn't really count as gravedigging if the post is actually something useful. Shh, it was a joke, settle down. RE: [MyBB] Improved password encryption. - Eclipse - 01-04-2015 (01-04-2015, 12:56 AM)Senpai Wrote: Shh, it was a joke, settle down. How was your first time with a jew? OT: It's hard to judge emotion over the internet. Shh. Seriously OT: This looks like it'd take a while, and yes, a better encryption algorithm would be preferable. RE: [MyBB] Improved password encryption. - phyrrus9 - 01-04-2015 (01-04-2015, 12:59 AM)Eclipse Wrote: How was your first time with a jew? Actually, it was pretty amazing ![]() Quote:OT: It's hard to judge emotion over the internet. Shh. Yeah, if we implemented something good, we wouldn't have to worry about DB leaks as much. I recommended it RE: [MyBB] Improved password encryption. - lux - 01-04-2015 Or you could over complicate shit and parse in the userID and times that by pi, then concat it to the string pre-hash. RE: [MyBB] Improved password encryption. - Kizaru - 01-04-2015 (01-04-2015, 03:06 AM)phyrrus9 Wrote: Actually, it was pretty amazing I recommend looking into this then https://github.com/TacticalCode/MyBBcrypt/blob/26918b2a37c9013eaa43abb1ea57663e21dc1138/inc/functions_user.php It implements bcrypt into mybb. RE: [MyBB] Improved password encryption. - phyrrus9 - 01-04-2015 Looks REALLY simple... I should write a RSA version ![]() Maybe RSA encrypt the entire database, so every time you query something it has to RSA decrypt it for validation or something. Hmm, neat. RE: [MyBB] Improved password encryption. - warstrike - 01-04-2015 use sha384+salt or bcrypt+salt. |