The John Morris Show

JMS240: Secure User Authenticaion and Cryptographically Secure Tokens in PHP


Listen Later

A common problem in PHP is creating cryptographically secure tokens for user authentication. Think "remember me" and password reset features. Functions like rand(), mt_rand() and uniqid() simply aren't enough. And, without "resource-improbable" tokens... it's only a matter of time for a hacker to break your authentication and get int your application.Fortunately, PHP 5.6 and 7 have added the necessary functions for us to creating cryptographically secure tokens, prevent timing attacks and mitigate data hacks. That latest in all this in this episode.Show notes and sources: https://www.johnmorrisshow.com/240

Hosted on Acast. See acast.com/privacy for more information.

...more
View all episodesView all episodes
Download on the App Store

The John Morris ShowBy John Morris

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

29 ratings