Beefy Boxes and Bandwidth Generously Provided by pair Networks
laziness, impatience, and hubris

Re: encryption and decryption

by radiantmatrix (Parson)
on Apr 01, 2008 at 15:02 UTC ( #677770=note: print w/replies, xml ) Need Help??

in reply to encryption and decryption

First, understand that security is harder than you think it is. I'm a security professional, and every day I still discover that security is harder than I thought in some way.

It concerns me that you're asking about "decryption" for passwords. Password-based authentication systems that are any kind of secure never decrypt anything. Instead, they store a one-way (i.e. irreversible) hash of the password. Then, when a user enters a password, the same hash algorithm is applied to it -- if that hash matches the stored hash, then the passwords were the same.

If this is what you want to do, I strongly suggest looking at using Crypt::Eksblowfish::Bcrypt. The Bcrypt algorithm is similar to crypt, but has several very nice security features. This algorithm is the default for FreeBSD as well -- widely considered one of the most security-conscious OS's available.

On the off chance that you are really needing to store an encrypted password that needs to be decrypted (for example, if you'll be using the password to log into some service automatically, and want to store it securely), I suggest using AES; this is also known as Rijndael. You'll need Crypt::CBC and Crypt::Rijndael for this purpose.

Ramblings and references
The Code that can be seen is not the true Code
I haven't found a problem yet that can't be solved by a well-placed trebuchet

Log In?

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://677770]
[Eily]: I still don't understand how the Turkish AA fit into the German+Czech joke though :P
[LanX]: new Firefox + cb sidebar do random auto expand on submit
[LanX]: probably need to start pm discussion
[LanX]: they have a constitutional referendum in turkey, kind of "do you want a dictator" and everybody opting no gets problems ...
[Corion]: LanX: Random Auto Expand?
[Corion]: LanX: Well, everybody opting "yes" will also get problems. The question is more like "Do you want problems now or problems later?"

How do I use this? | Other CB clients
Other Users?
Others making s'mores by the fire in the courtyard of the Monastery: (9)
As of 2017-03-27 12:11 GMT
Find Nodes?
    Voting Booth?
    Should Pluto Get Its Planethood Back?

    Results (319 votes). Check out past polls.