Password Hashing in PHP

preview_player
Показать описание
An unconference talk that I gave at the PHP North West 2012 conference.

It explores the ways that password hashes are attacked, and how those attacks can be prevented. It also goes into some tools that are available to properly hash passwords for storage in PHP. We introduce the new Password Hashing API that will be available in PHP 5.5...

References:

Tools:
Рекомендации по теме
Комментарии
Автор

Good stuff, great to see some numbers. Glad you filmed it as I never made it upstairs to the uncon.

GenericUsernameOne
Автор

Thank you!
You just explained something that was getting a bit difficult for me to understand just by reading in manuals. :)
Keep up the awsome work buddy.

PEDREX
Автор

Great explanation, thank you for clearing up some things for me :)

RamboFrede
Автор

FYI: the bcrypt crack that was shown in the demo finally finished. In a grand total of 15 days 9 hours 24 minutes. To crack what MD5 cracked in 15 seconds... :-D

AnthonyFerrara
Автор

I've always called it "PH Pass" (as in PASSword), but I there's something I like about about the way you say "PHP Ass".

motty
Автор

thanks for your great tutos, i want just ask you about laravel... what do you think about it ? it is a great framework

ezlearnup
Автор

Can all of these hacks, only be done if the database leaked or something?

Katatonya
Автор

Turned the talk off after discussion about legal liability.

somethingnevertaken
Автор

Why is this still a thing, just because you use a Mac or Windows or whatever you use does not change your ability.

AaronFisher
Автор

wow i didnt understand shit so confusing nube to this

henryabirafeh