DEV Community

Discussion on: PHP Security: Passwords

Collapse
 
tadman profile image
Scott Tadman

Since the application must keep the AES key around somewhere handy, in the event of a compromise it's going to get stolen as well and then your encryption is worthless as they have the key.

From there dealing with a single layer of HMAC is pretty trivial.