dongpu2694 2011-01-29 01:18
浏览 58
已采纳

通过HTTPS在MySQL和PHP中进行密码加密

Is it really necessary to encrypt passwords using md5() or sha1() WITH SALT (or even at all) if the connection takes place over HTTPS?

Thanks in advance

  • 写回答

3条回答 默认 最新

  • douyi0219 2011-01-29 01:21
    关注

    If somebody hacks into your server, or gets ahold of a backup, and the passwords aren't aren't hashed with a salt, then they will have access to all your users passwords. It's very much necessary to salt and hash your passwords. Probably more important than using HTTPS to authenticate.

    They actually should both be used, as they solve completely different problems. HTTPS is used to protect the password as it travels over the internet to your servers. Hashing and salting is used to protect the password when it is stored on your servers.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?

悬赏问题

  • ¥15 BP神经网络控制倒立摆
  • ¥20 要这个数学建模编程的代码 并且能完整允许出来结果 完整的过程和数据的结果
  • ¥15 html5+css和javascript有人可以帮吗?图片要怎么插入代码里面啊
  • ¥30 Unity接入微信SDK 无法开启摄像头
  • ¥20 有偿 写代码 要用特定的软件anaconda 里的jvpyter 用python3写
  • ¥20 cad图纸,chx-3六轴码垛机器人
  • ¥15 移动摄像头专网需要解vlan
  • ¥20 access多表提取相同字段数据并合并
  • ¥20 基于MSP430f5529的MPU6050驱动,求出欧拉角
  • ¥20 Java-Oj-桌布的计算