in reply to hiding passwords

I just want to inject some paranoidal input into this discussion, hanging on to the OP's mentioning of MD5 in his post.

The MD5 hash algorithm has been recently subjected to several successful attacks, and is now generally believed to be compromised and not safe in the cryptographic community.

SHA-256 may be used to be secure, via the Digest::SHA module.

Replies are listed 'Best First'.
Re^2: hiding passwords
by sgifford (Prior) on Jun 14, 2005 at 19:54 UTC
    None of the attacks on MD5 so far are relevant for one-way hashes of passwords, though moving to SHA-256 may not be a bad idea anyways.