Login Register






How to hash password correctly in PHP? filter_list
Author
Message
RE: How to hash password correctly in PHP? #22
As @Ecks and others have mentioned, salting is imperative in hashing passwords (and Computerphile is great). Without salts, you'll have a repeat of the Adobe incident if your database is compromised. They didn't salt their hashes (so identical passwords had identical hashes) and stored password hints, so it was essentially a giant crossword puzzle for the hackers.

Additionally, DO NOT USE MD5 or any other algorithm with a documented, applied (i.e. not theoretical) attack. I don't care that MD5 is faster or takes up less space (which is pretty much negligible anyway); if you don't want to be vulnerable to proven attacks, don't use it. See the following links for explanations/data.
https://en.wikipedia.org/wiki/Cryptograp...h_function
https://en.wikipedia.org/wiki/Hash_funct...ty_summary

The following code should serve as a viable hashing process. See hash_algos() for a list of algorithms.
Code:
<?php // change to desired algorithm const HASH="sha512"; function hash_passwd($pass,$len=8,$binary=true){ $salt=""; // generate salt $len characters long for($i=0;$i<$len;$i++) $salt.=chr(mt_rand()%255); return array( "hash" => hash(HASH,$hash.$salt,$binary), "salt" => $salt ); }
Use the "hash" and "salt" keys to access their respective values in the array returned from hash_passwd().

Finally, use hash_equals() to mitigate timing attacks when comparing hashes.

Edit: @Pikami: SHA-256 and SHA-512 are viable for cryptographic use but you're correct in respect to SHA-1, which has been documented as cracked several times.
(This post was last modified: 08-27-2017, 02:37 AM by Inori.)
It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.

Reply





Messages In This Thread
How to hash password correctly in PHP? - by Sikom - 05-29-2017, 10:10 PM
RE: How to hash password correctly in PHP? - by Inori - 08-27-2017, 02:31 AM