Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #17069
| From | Thomas 'PointedEars' Lahn <PointedEars@web.de> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | Re: HTTPS data in a form |
| Date | 2016-09-19 23:28 +0200 |
| Organization | PointedEars Software (PES) |
| Message-ID | <3934285.LvFx2qVVIh@PointedEars.de> (permalink) |
| References | <e8880b4e-3407-4166-abf5-cadeae30c633@googlegroups.com> <52647a62-05fe-ade7-9de8-e434f646aad9@arnowelzel.de> <2368565.mvXUDI8C0e@PointedEars.de> <0538bd0a-15af-6afe-260c-38fb970c56d9@arnowelzel.de> |
Arno Welzel wrote: > "If I have a form where there's a username and a password, and I'd like > only the *password* to be encrypted before being sent [...]" OK, then the correct answer is that it is foolish to want that because the used encryption/hashing algorithm would have to reside on the client in the form of a client-side script *for every attacker plain to see* (obfuscation is _not_ protection). Where passwords are involved, the form data – password *and* username –, SHOULD¹ be sent via an encrypted *connection* (HTTPS or, IOW, HTTP over a TLS-1.2-encrypted TCP connection; minimum cipher strength should be 256 bits). The password SHOULD NOT be stored on the server at all (and maybe not even the username verbatim), but only its checksum (“hash”) *that is computed by the server and SHOULD never leave the server*. (Computing a hash is _not_ encryption.) Checking a username/password then means comparing the hash of the provided username/password against the stored hash(es) *server-side*. The hash should be computed using a strong hashing algorithm (so _not_ plain MD5 or SHA1, but rather the likes of bcrypt [default for password_hash() since PHP 5.5.0] and scrypt with a strong salt [using the default for password_hash() is recommended as of PHP 7.0.0 as the “salt” option was deprecated]). See also: <https://www.owasp.org/index.php/Authentication_Cheat_Sheet> pp. <https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet> pp. <http://php.net/password_hash> However, it is equally possible that the OP has a basic misconception about “password encryption”. Hiding a password, e.g. by masking characters (e.g. using the HTML type="password" attribute), is _not_ “password encryption” either. _________ ¹ see RFC 2119 for the definitions of all-uppercase requirement levels -- PointedEars Zend Certified PHP Engineer <http://www.zend.com/en/yellow-pages/ZEND024953> | Twitter: @PointedEars2 Please do not cc me. / Bitte keine Kopien per E-Mail.
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
HTTPS data in a form bit-naughty@hotmail.com - 2016-09-15 21:45 -0700
Re: HTTPS data in a form "J.O. Aho" <user@example.net> - 2016-09-16 07:52 +0200
Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-17 15:57 +0200
Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-17 21:17 +0200
Re: HTTPS data in a form Jerry Stuckle <jstucklex@attglobal.net> - 2016-09-17 17:02 -0400
Re: HTTPS data in a form "Peter H. Coffin" <hellsop@ninehells.com> - 2016-09-21 11:33 -0500
Re: HTTPS data in a form Jerry Stuckle <jstucklex@attglobal.net> - 2016-09-23 08:47 -0400
Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-24 22:11 +0200
Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-19 21:36 +0200
Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-19 23:28 +0200
Re: HTTPS data in a form "Christoph M. Becker" <cmbecker69@arcor.de> - 2016-09-19 23:44 +0200
Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-19 23:57 +0200
Re: HTTPS data in a form "Christoph M. Becker" <cmbecker69@arcor.de> - 2016-09-20 19:00 +0200
Re: HTTPS data in a form Jerry Stuckle <jstucklex@attglobal.net> - 2016-09-19 21:00 -0400
Re: HTTPS data in a form Stefan+Usenet@Froehlich.Priv.at (Stefan Froehlich) - 2016-09-20 05:59 +0000
Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-20 15:40 +0200
Re: HTTPS data in a form "J.O. Aho" <user@example.net> - 2016-09-20 18:39 +0200
Re: HTTPS data in a form Jerry Stuckle <jstucklex@attglobal.net> - 2016-09-20 14:36 -0400
Re: HTTPS data in a form Stefan+Usenet@Froehlich.Priv.at (Stefan Froehlich) - 2016-09-20 21:04 +0000
Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-24 21:58 +0200
Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-26 19:43 +0200
Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-23 09:14 +0200
Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-24 22:00 +0200
Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-26 19:44 +0200
Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-20 08:20 +0200
Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-20 15:41 +0200
Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-23 09:02 +0200
Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-24 22:06 +0200
Re: HTTPS data in a form Arno Welzel <usenet@arnowelzel.de> - 2016-09-26 19:49 +0200
Re: HTTPS data in a form Richard Damon <Richard@Damon-Family.org> - 2016-09-18 14:22 -0400
Re: HTTPS data in a form Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2016-09-19 23:36 +0200
Re: HTTPS data in a form Jerry Stuckle <jstucklex@attglobal.net> - 2016-09-19 21:03 -0400
Re: HTTPS data in a form "Peter H. Coffin" <hellsop@ninehells.com> - 2016-09-21 11:29 -0500
csiph-web