What are the potential security risks of storing passwords in a database without encryption?
Storing passwords in a database without encryption leaves them vulnerable to unauthorized access in case of a data breach. To mitigate this risk, passwords should be securely hashed before storing them in the database. This ensures that even if the database is compromised, the actual passwords cannot be easily retrieved.
$hashed_password = password_hash($password, PASSWORD_DEFAULT);