4 ms·
That would have been standard 10 years ago, but these days, it's not very effective and, unfortunately, it's still a very common scheme. You're better off with:
by eksith 13y ago
That would have been standard 10 years ago, but these days, it's not very effective and, unfortunately, it's still a very common scheme. You're better off with:
function rHash( $rounds, $data, $salt ) {
$data = $data . $salt;
while( $rounds > 0 ) {
$data = hash( 'tiger160,4', $data );
$rounds--;
}
}
And call $stored = rHash( ( registered month + year ), $password );
Or even the trusty old...
$stored = crypt( $password, '$2y$14$' . $salt . '$' );
If you're on PHP > 5.4 ( some hosts are still on older versions ), you should check out password_hash() : http://php.net/manual/en/function.password-hash.php http://php.net/manual/en/function.password-hash.php
Edit: Fixed some typos.