Password Hashing

Password Hashing with password_hash and password_verify

Never store a password, and never hash one with md5(), sha1() or hash('sha256', ...): those are fast, exactly what an attacker with a stolen table wants. Use password_hash(), a slow salted algorithm built for the job, and password_verify() to check a login. The salt is generated and embedded, so you store one string and manage none.

Hashing a password and verifying itPHP
$hash = password_hash('correct horse battery staple', PASSWORD_DEFAULT);
echo $hash, "\n";
var_dump(password_verify('correct horse battery staple', $hash), password_verify('wrong', $hash));
echo password_get_info($hash)['algoName'], "\n";
Output
$2y$12$h1MseevPFQrp//5hD/4dueeBrAym/NJJZYpnOyudZCSZT0S4VTdfm
bool(true)
bool(false)
bcrypt

PASSWORD_DEFAULT is bcrypt today (id 2y) and is allowed to change as PHP adopts stronger defaults, so store the full string rather than assume a length. The hash records its algorithm, cost and salt, so password_verify() needs only the password and that string; store it in VARCHAR(255). Two pitfalls: bcrypt silently truncates at 72 bytes, and passing the whole hash back into password_hash() double-hashes it.