Salted Password Hashing – Doing it Right

Diskuse na Hacker News: Salted Password Hashing – Doing it Right
This article looks great for anybody who wants to know the details. But "doing it right" is much simpler, and doesn't really need an article:
"Use an accepted key derivation function, such as PBKDF2, bcrypt or scrypt".
password_hash("password", PASSWORD_BCRYPT);
ircmaxell/password_compat · GitHub
23. 2. 2014 22:29:39
