RE: How to hash password correctly in PHP? 08-28-2017, 08:37 PM
#27
(08-28-2017, 06:56 PM)Mystique Wrote: It takes the pass and hashes in md5 (already non reversible but easy to dictionary attack), then takes that and base64 encrpyts it using then bcrypts the base64 encrypt. (Overkill a bit)
Tbh you'd be fine with just password_hash($pass, PASSWORD_BCRYPT);
Again, DO NOT USE MD5 IN PRODUCTION. As I outlined in my post, and as you said here, it's extremely vulnerable and should not be used.
It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.
don't have much in the first place, who feel the new currents and ride them the farthest.