password_hash($password, PASSWORD_BCRYPT)
From version 5.5 that is, but you can get a compatibility library for older versions. password_hash($password, PASSWORD_BCRYPT)
From version 5.5 that is, but you can get a compatibility library for older versions.Basically, bcrypt randomly generates a long, probably-unique salt for every hashed password, and the salt is stored along with the hash by simply concatenating it to the string (e.g. “randomsaltZdR3/passwordhashMP2tA”). To check an incoming password against the stored hash, bcrypt splits the stored string on ‘/’ to extract the salt, hashes `password+salt`, and compares that hash against the one to the right of ‘/’ in the stored string.
This means that you just whack the hash and the password the user entered into password_verify(...) and it will tell you if you have a match - you don't have to keep track of the four parameters.
The beauty of that when a stronger algorithm comes out or you want to increase the cost factor of your passwords, you just change the hashing code and you don't have to do anything fancy to not break all your old hashes.
You can also use the password_needs_rehash(...) function once you verify to see if you should rehash the password to bring it up to the new level.
The compatibility library to use for PHP <5.5 is Antony Ferrara's password_compat: https://github.com/ircmaxell/password_compat.
The most recent version of the ASP.net Membership provider offers this hashing algorithm as a built in option.
http://stackoverflow.com/questions/481160/is-bcrypt-a-good-h...