Using a more secure hashing algorithm with CakePHP

Viewed 2079

By default, CakePHP seems to use the SHA1 algorithm to hash passwords and only seems to offer SHA256 as an alternative:

http://api.cakephp.org/view_source/security#line-86

I wanted to switch to a more secure password hashing solution before I make my application public to save future headaches when switching to a more secure hashing algorithm. I've looked around for some guides on using bcrypt or something similar but they all seem to be for older versions of Cake, or implement the hashing poorly.

Is there a guide somewhere that can show me how to integrate better password hashing without changing any code in my models or controllers?

Also, a little side question, why did the Cake devs only include SHA password hashing in their release? It's common knowledge that SHA is a broken hashing algorithm for passwords, it just seems to me that such a reputable framework wouldn't have overlooked this.

1 Answers
Related