4 ms·
http://codahale.com/how-to-safely-store-a-password/ http://codahale.com/how-to-safely-store-a-password/ or PBKDF2 is also a good solution. the tl;dr version is:
by throwaway125 14y ago
http://codahale.com/how-to-safely-store-a-password/ http://codahale.com/how-to-safely-store-a-password/ or PBKDF2 is also a good solution.
the tl;dr version is: sha1(md5(pw + salt)) is too fast to be good, crackers can run millions of attempts per second if they have access to the hash.
- stouset 14y agoTLDR 2; Stop inventing your own cryptography. This doesn't just mean "cryptographic cipher". If you're passing data into cryptographic functions and the parameter names don't conceptually match what you're putting in them, you're probably doing voodoo cryptography.