How can PHP programmers ensure secure password protection in their code?
PHP programmers can ensure secure password protection in their code by using strong encryption methods like bcrypt, salting the passwords before hashing, and enforcing password complexity requirements. It's also important to securely store the hashed passwords and never store them in plain text.
// Hashing and salting passwords using bcrypt
$password = "mypassword123";
$salt = openssl_random_pseudo_bytes(22);
$options = [
'cost' => 12,
'salt' => $salt,
];
$hashedPassword = password_hash($password, PASSWORD_BCRYPT, $options);
// Verify password
if (password_verify($password, $hashedPassword)) {
echo "Password is correct";
} else {
echo "Password is incorrect";
}