What are some best practices for structuring tables in a PHP MySQL database to avoid data theft?

To avoid data theft in a PHP MySQL database, it is important to properly structure tables with appropriate data types, lengths, and constraints. Use encryption techniques for sensitive data such as passwords and personal information. Implement input validation and parameterized queries to prevent SQL injection attacks. Regularly update and maintain the database to fix any vulnerabilities.

// Example of creating a users table with proper structure and encryption for passwords

CREATE TABLE users (
    id INT AUTO_INCREMENT PRIMARY KEY,
    username VARCHAR(50) NOT NULL,
    email VARCHAR(100) NOT NULL,
    password VARCHAR(255) NOT NULL,
    created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
    updated_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
);

// Example of encrypting passwords before storing them in the database

$password = 'secret_password';
$hashed_password = password_hash($password, PASSWORD_DEFAULT);

// Example of validating user input and using parameterized queries to prevent SQL injection

$username = $_POST['username'];
$email = $_POST['email'];
$password = $_POST['password'];

$stmt = $pdo->prepare("INSERT INTO users (username, email, password) VALUES (:username, :email, :password)");
$stmt->bindParam(':username', $username);
$stmt->bindParam(':email', $email);
$stmt->bindParam(':password', $hashed_password);
$stmt->execute();