php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #55215 md5 page should display a warning not to be used for passwords
Submitted: 2011-07-15 12:44 UTC Modified: 2011-07-16 23:47 UTC
Votes:4
Avg. Score:4.8 ± 0.4
Reproduced:3 of 3 (100.0%)
Same Version:3 (100.0%)
Same OS:3 (100.0%)
From: ss23 at ss23 dot geek dot nz Assigned: frozenfire (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: ss23 at ss23 dot geek dot nz
New email:
PHP Version: OS:

 

 [2011-07-15 12:44 UTC] ss23 at ss23 dot geek dot nz
Description:
------------
Currently, far too many users think that md5() is suitable for storing passwords 
in their database. A warning that informs them its not, along with a link to an 
appropriate replacement like crypt() would help.
This could be appropriate for pages likes sha1() and hash() too.


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-07-15 12:51 UTC] joey@php.net
It might also be nice to include a reference to a good explanation of why it's 
not, for example, Thomas Ptacek's article from a few years back.
 [2011-07-16 18:56 UTC] frozenfire@php.net
-Status: Open +Status: Assigned -Assigned To: +Assigned To: frozenfire
 [2011-07-16 22:23 UTC] frozenfire@php.net
Automatic comment from SVN on behalf of frozenfire
Revision: http://svn.php.net/viewvc/?view=revision&revision=313306
Log: Added a "Password Hashing" faq, and notes to md5 and sha1 functions. Relates to bug #55215.
 [2011-07-16 23:47 UTC] frozenfire@php.net
-Status: Assigned +Status: Closed
 [2011-07-16 23:47 UTC] frozenfire@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.

Other than a few tweaks to potentially be made, this is resolved.
 [2011-07-17 06:50 UTC] tyrael@php.net
maybe we should mention that there are pre-computed databases(rainbow tables) and 
online services for md5/sha1 lookups, so in the majority of the password the brute 
forcing is already done.
it would be also useful to mention if somehow you need to use any of the fast 
algos, you should salt the password before hashing.
what do you think?

Tyrael
 [2011-07-17 07:10 UTC] tyrael@php.net
nevermind, I've just miss the lengthly discussion about this on irc.

Tyrael
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 22:00:01 2026 UTC