What are some best practices for securely storing user passwords in a MySQL database when implementing a registration and login system in PHP?

When storing user passwords in a MySQL database, it is essential to securely hash the passwords using a strong hashing algorithm like bcrypt. This helps protect user passwords in case of a data breach. Additionally, using prepared statements to prevent SQL injection attacks is crucial for securing the database.

// Hashing user password before storing in the database
$password = $_POST['password'];
$hashed_password = password_hash($password, PASSWORD_DEFAULT);

// Using prepared statements to prevent SQL injection
$stmt = $pdo->prepare("INSERT INTO users (username, password) VALUES (:username, :password)");
$stmt->bindParam(':username', $_POST['username']);
$stmt->bindParam(':password', $hashed_password);
$stmt->execute();