Sinisterly
Tutorial [MyBB] Improved password encryption. - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: PHP (https://sinister.li/Forum-PHP)
+--- Thread: Tutorial [MyBB] Improved password encryption. (/Thread-Tutorial-MyBB-Improved-password-encryption)

Pages: 1 2 3 4 5 6 7


RE: [MyBB] Improved password encryption. - Eclipse - 01-04-2015

@Oni, get your ass here.


RE: [MyBB] Improved password encryption. - The Protagonist - 01-04-2015

(01-04-2015, 06:53 AM)Lux Wrote: Or you could over complicate shit and parse in the userID and times that by pi, then concat it to the string pre-hash.
wouldn't really make a difference. I would just parse out the last 5 characters for salts and first 32 characters for pass hash. No matter what fuckery you do like that, it won't make a difference if they know what they're doing. They'd simply read the code and reverse it. You should try making things actually more secure rather than seemingly more secure.


RE: [MyBB] Improved password encryption. - Lain - 01-04-2015

(01-04-2015, 08:41 AM)phyrrus9 Wrote: Looks REALLY simple... I should write a RSA version Tongue

Maybe RSA encrypt the entire database, so every time you query something it has to RSA decrypt it for validation or something. Hmm, neat.

I've considered coding something similar myself, but put it aside as a large problem would be a large decrease in page load speeds.


RE: [MyBB] Improved password encryption. - phyrrus9 - 01-04-2015

(01-04-2015, 03:35 PM)Senpai Wrote: I've considered coding something similar myself, but put it aside as a large problem would be a large decrease in page load speeds.

I almost started writing it in php last night..

look here


RE: [MyBB] Improved password encryption. - Lain - 01-04-2015

(01-04-2015, 08:21 PM)phyrrus9 Wrote: I almost started writing it in php last night..

look here

And that won't slow it down every time the page loads and the server has to decrypt/crypt multiple times?


RE: [MyBB] Improved password encryption. - phyrrus9 - 01-04-2015

(01-04-2015, 09:26 PM)Senpai Wrote: And that won't slow it down every time the page loads and the server has to decrypt/crypt multiple times?
Speed vs security your choice


RE: [MyBB] Improved password encryption. - Lain - 01-04-2015

(01-04-2015, 09:28 PM)phyrrus9 Wrote: Speed vs security your choice

This.


RE: [MyBB] Improved password encryption. - phyrrus9 - 01-04-2015

(01-04-2015, 09:30 PM)Senpai Wrote: This.
A crucial part would be only encrypting essentials (user table, admin stuff, etc) that way the load time is only dropped by a few mils.


RE: [MyBB] Improved password encryption. - Lain - 01-04-2015

(01-04-2015, 09:33 PM)phyrrus9 Wrote: A crucial part would be only encrypting essentials (user table, admin stuff, etc) that way the load time is only dropped by a few mils.

Would you go as far as encrypting posts?


RE: [MyBB] Improved password encryption. - Oni - 01-05-2015

I'd love to do something like this for SL... Although there's no way I'm doing this manually 8,000 times.