And concatenate the first few characters of the user name (or a random value) with the password before hashing it, to prevent dictionary attacks.

http://phpsec.org/articles/2005/password-hashing.html


Edited by andy (10/05/2007 12:32)
_________________________
Remind me to change my signature to something more interesting someday