This blog post provides good information about password hashing. The main point of this article is to use strong encryption and make attackers life hard. So if someone gains access to database, attacker could figure out your password using a brute force or rainbow tables.
You should follow me on twitter here or grab rss feed to keep track of new changes.
Featured Articles:
- 30 Handy Bash Shell Aliases For Linux / Unix / Mac OS X
- Top 30 Nmap Command Examples For Sys/Network Admins
- 25 PHP Security Best Practices For Sys Admins
- 20 Linux System Monitoring Tools Every SysAdmin Should Know
- 20 Linux Server Hardening Security Tips
- Linux: 20 Iptables Examples For New SysAdmins
- Top 20 OpenSSH Server Best Security Practices
- Top 20 Nginx WebServer Best Security Practices
- 20 Examples: Make Sure Unix / Linux Configuration Files Are Free From Syntax Errors
- 15 Greatest Open Source Terminal Applications Of 2012

- My 10 UNIX Command Line Mistakes
- Top 10 Open Source Web-Based Project Management Software
- Top 5 Email Client For Linux, Mac OS X, and Windows Users
- The Novice Guide To Buying A Linux Laptop











{ 2 comments… read them below or add one }
Yep, recent advances in CPU power allow recovering poorly hashed passwords.
Besides the (not so obvious to some, but required) salt, there are a couple of rules:
- password minimum length (unsalted passwords up to 8/9 chars can be easily recovered)
- variable salt (you can store the salt for each password in the db as well, this increases it’s security exponentially)
- strong hash function (md5 is considered weak nowadays, sha1 or even better sha256 is the way to go)
… but most importantly, NEVER store passwords in plaintext, as i still see in many sites that send you your original password on recovery… :/
How do you do the variable salt thing in PHP?