What are the potential security risks of storing passwords in a database using MD5 encryption and how can these risks be mitigated?
Storing passwords in a database using MD5 encryption poses a security risk because MD5 is a weak hashing algorithm that can be easily cracked using modern computing power. To mitigate this risk, it is recommended to use stronger hashing algorithms such as bcrypt or Argon2 for password storage.
// Hashing the password using bcrypt
$password = 'password123';
$hashed_password = password_hash($password, PASSWORD_BCRYPT);
// Verifying the password
if (password_verify($password, $hashed_password)) {
echo 'Password is valid!';
} else {
echo 'Invalid password.';
}