Sinisterly
Tutorial [MyBB] Improved password encryption. - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: PHP (https://sinister.li/Forum-PHP)
+--- Thread: Tutorial [MyBB] Improved password encryption. (/Thread-Tutorial-MyBB-Improved-password-encryption)

Pages: 1 2 3 4 5 6 7


RE: [MyBB] Improved password encryption. - Yani - 02-06-2015

Well, to take it up a notch, what would be better is to use a unique hash for every user, this way the salt wouldn't be useless once it's figured out. (after cracking 2 or 3 accounts) And a salt can also be randomly generated trough MySQL, but you'll first have to implement a salt generating code for the register process and edit your login process to load the salt first. Link: http://stackoverflow.com/questions/16737910/generating-a-random-unique-8-character-string-using-mysql


RE: [MyBB] Improved password encryption. - netspace - 05-20-2015

I've once used a combination of a secret string and users' emails as a salt.

$secret_string = "ih3o4i2h3455gh";
$user_email = "johndoe@Gmail.com"; // retrieved from db
$salt = md5($secret_string . $user_email);

The only disadvantage is that the password hashes that are store in your DB would need to be updated
whenever users change their email.


RE: [MyBB] Improved password encryption. - Lain - 05-27-2015

I no longer do this myself and instead am hashing the passwords on my forum with bcrypt.


RE: [MyBB] Improved password encryption. - Crypt - 05-27-2015

(10-28-2013, 04:38 AM)Kitsune Wrote: This makes it exceedingly difficult for an attacker to decrypt the password hashes on your forum.

No it doesn't; you don't decrypt hashes.


RE: [MyBB] Improved password encryption. - Lain - 05-27-2015

(05-27-2015, 12:51 AM)nothing.nobody Wrote: No it doesn't; you don't decrypt hashes.

bruteforce. you know what I meant.


RE: [MyBB] Improved password encryption. - netspace - 05-30-2015

How secure is bcrypt though?


RE: [MyBB] Improved password encryption. - Lain - 05-31-2015

(05-30-2015, 01:56 PM)netspace Wrote: How secure is bcrypt though?

Here's a great explanation that I didn't write:
[Image: 2f9e27089085b23ce910c59e642ba7df.png]

Whilst in the explanation, Yagmi used a work factor of 9, I use a significantly higher work factor, so that each hash takes 0.7s to generate.

This tutorial is old as fuck, dunno why people keep bumping it. Stressed


RE: [MyBB] Improved password encryption. - Vertigo - 06-18-2015

(10-28-2013, 04:38 AM)Kitsune Wrote: -SNIP-

Just doing 2-3 rounds doesn't cut down on used power. Since md5 only takes liek e^11 rounds, you need to pad things a bit better...

ripped this from an older project of mine.
Code:
/* <multi-round md5 hash logic> */ function md5_rounded($input){ $rounds = 50; /*- Set this number to how many times ("rounds") you want to pass the md5 hash through -*/ $i = 0; while (++$i <= $rounds){ $input = md5($input); } return $input; } /* </multi-round md5 hash logic> */

For the record, use php's Crypt() hash, as it is much better. Also, whenever you can...

use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt

Bonus points for using 90 round bcrypt, and then layering it another 90 rounds in php.


RE: [MyBB] Improved password encryption. - Lain - 06-18-2015

(06-18-2015, 04:43 AM)Vertigo Wrote: Just doing 2-3 rounds doesn't cut down on used power. Since md5 only takes liek e^11 rounds, you need to pad things a bit better...

ripped this from an older project of mine.
Code:
/* <multi-round md5 hash logic> */ function md5_rounded($input){ $rounds = 50; /*- Set this number to how many times ("rounds") you want to pass the md5 hash through -*/ $i = 0; while (++$i <= $rounds){ $input = md5($input); } return $input; } /* </multi-round md5 hash logic> */

For the record, use php's Crypt() hash, as it is much better. Also, whenever you can...

use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt use bcrypt

Bonus points for using 90 round bcrypt, and then layering it another 90 rounds in php.

You might wanna read the few posts before yours.


RE: [MyBB] Improved password encryption. - Vertigo - 06-18-2015

(06-18-2015, 10:01 AM)Kitsune Wrote: You might wanna read the few posts before yours.

Sorry I went full autism.