Is the php method md5() secure? Can it be used for passwords? [migrated]
- by awiebe
So executing a php script causes the form values to be sent to the server, and then they are processed.
If you want to store a password in your db than you want it to be a cryptographic hash(so your client side is secure, can you generate an md5 using php securely( without submitting the user:password pair in the clear), or is there an alternative standard method of doing this, without having the unecrypted pasword leaving the clients machine?
Sorry if this is a stupid question I'm kind of new at this.
I think this can be done somehow using https, and on that note if a site's login page does not use https, does that mean that while the databse storage is secure, the transportation is not?