Welcome!

PHP Authors: Liz McMillan, Carmen Gonzalez, Hovhannes Avoyan, Lori MacVittie, Trevor Parsons

Related Topics: PHP, Cloud Security

PHP: Article

Using PHP to Enhance Password Security

Converting a phrase to a seemingly random password using PHP

When dictating password policies to users, it is common for such policies to require that users generate passwords that contain a combination of uppercase and lowercase letters, as well as numbers and special characters. Moreover, it is well established that the strengths of such passwords are further enhanced if the passwords do not in any way resemble dictionary words, since minor substitutions of dictionary words and names are often included in the dictionaries used in dictionary-based attacks and in some rainbow table variants. Thus "D3veloper" would be a less than ideal password since potentially it's an easily guessed variant of the word "developer."

A common recommendation for dealing with this issue is to suggest the use of randomly generated passwords such as "0Y=/S?tV". However, such passwords often pose great difficulty for many users to remember, which can lead to passwords being written down and hence result in a decrease rather than an increase in security. To resolve this issue, a technique has recently been suggested whereby the user turns an easily remembered phrase into a seemingly random password by taking the first letter of each word in the phrase and then performing character substitutions in order to introduce other character types such as numbers and special characters.

Thus, the user would take a phrase such as "The quick brown fox jumped over the lazy dog" and turn it into the character string "Tqbfjotld." They could then pick a character and replace it with an easily remembered number and then pick a second character and replace it with an easily remembered special character. Thus if the person's "b"irthday was on the 5th, perhaps they would associate "b" with number "5," and if they liked the J# programming language, perhaps they would associate "j" with "#."  Thus "b" and "j" could be replaced with their associated characters to make the password "Tq5f#otld"; a seemingly random password that can be recalled by the user using easy to remember mnemonic tricks.

This article demonstrates a small PHP5 script that can be used to convert user supplied phrases into such a seemingly random password. Before the PHP code itself is executed, however, an HTML form is initially used to allow the user to supply the phrase they are interested in, via text box, and specify their choice in character substitutions, via drop down boxes. The HTML code can be found in Listing 1 and a screenshot of the HTML form found in Figure 1.

Figure 1: The HTML interface used to accept user inputs

It is important to note that the HTML script uses the post action to submit the various HTML control values to the PHP script as follows. The text box element is named "Text" and is used to allow the user to enter his phrase of choice. Four drop down boxes are also used, where the drop down box "NumLet" allows the user to specify the letter that the user wants to replace with the number found in the drop down box "Num." Likewise, the "SpecLet" drop down box allows the user to specify the letter that the user wants to replace with the special character found in the drop down box "Spec."

Upon Execution, the PHP script accepts the values of these HTML controls and assigns them to like named variables as follows:

$passwd="";
$Phrase=$_POST['Text'];
$NumLet=$_POST['NumLet'];
$Num=$_POST['Num'];
$SpecLet=$_POST['SpecLet'];
$Spec=$_POST['Spec'];

Next, the PHP script uses the explode function to split the $Phrase string into an array of individual words (substrings), by using a space as the delimiter.  A for loop is then used to loop through all of the substrings and a regular expression, which makes use of the predefined "\w" subpattern used to identify the first letter of each substring.  The identified letter is then appended to the string stored in the variable $passwd to produce a string the consists of the first letter found in each substring as demonstrated below:

$words=explode(" ", $Phrase);
foreach($words as $word){
preg_match('/\w/', $word, $matches);
$passwd=$passwd . $matches[0];
}

Two additional regular expressions are then utilized to perform a match and replace operation, whereby the two user-specified letters are replaced with the respective user-selected number and special character, as shown below:

$passwd=preg_replace("/($NumLet)/i", "$Num", $passwd);
$passwd=preg_replace("/($SpecLet)/i", "$Spec", $passwd);

The password is then printed to the screen and to yield output like the representative one shown in Figure 2.

Figure 2: The seemingly random password that results from the information specified in Figure 1.

All in all, this article demonstrates a PHP5 script that can be used to automate the conversion of any user-specified phrase into a seemingly random password. Both the HTML code and the PHP5 code (see Listing 2 for complete code) can be easily modified to enhance compliance with organizational policies and as such can provide a useful tool for enhancing password policy compliance and password security throughout any organization. A version of the software is also being hosted at http://www.insilicobiotechnologies.com/PasswdMkr/PhrasetoPassIn.html for anyone who wishes to make use of the application in the format specified here.

More Stories By Christopher Frenz

Christopher Frenz is the author of "Visual Basic and Visual Basic .NET for Scientists and Engineers" (Apress) and "Pro Perl Parsing" (Apress). He is a faculty member in the Department of Computer Engineering at the New York City College of Technology (CUNY), where he performs computational biology and machine learning research.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


IoT & Smart Cities Stories
Machine learning has taken residence at our cities' cores and now we can finally have "smart cities." Cities are a collection of buildings made to provide the structure and safety necessary for people to function, create and survive. Buildings are a pool of ever-changing performance data from large automated systems such as heating and cooling to the people that live and work within them. Through machine learning, buildings can optimize performance, reduce costs, and improve occupant comfort by ...
According to Forrester Research, every business will become either a digital predator or digital prey by 2020. To avoid demise, organizations must rapidly create new sources of value in their end-to-end customer experiences. True digital predators also must break down information and process silos and extend digital transformation initiatives to empower employees with the digital resources needed to win, serve, and retain customers.
Early Bird Registration Discount Expires on August 31, 2018 Conference Registration Link ▸ HERE. Pick from all 200 sessions in all 10 tracks, plus 22 Keynotes & General Sessions! Lunch is served two days. EXPIRES AUGUST 31, 2018. Ticket prices: ($1,295-Aug 31) ($1,495-Oct 31) ($1,995-Nov 12) ($2,500-Walk-in)
Business professionals no longer wonder if they'll migrate to the cloud; it's now a matter of when. The cloud environment has proved to be a major force in transitioning to an agile business model that enables quick decisions and fast implementation that solidify customer relationships. And when the cloud is combined with the power of cognitive computing, it drives innovation and transformation that achieves astounding competitive advantage.
René Bostic is the Technical VP of the IBM Cloud Unit in North America. Enjoying her career with IBM during the modern millennial technological era, she is an expert in cloud computing, DevOps and emerging cloud technologies such as Blockchain. Her strengths and core competencies include a proven record of accomplishments in consensus building at all levels to assess, plan, and implement enterprise and cloud computing solutions. René is a member of the Society of Women Engineers (SWE) and a m...
IoT is rapidly becoming mainstream as more and more investments are made into the platforms and technology. As this movement continues to expand and gain momentum it creates a massive wall of noise that can be difficult to sift through. Unfortunately, this inevitably makes IoT less approachable for people to get started with and can hamper efforts to integrate this key technology into your own portfolio. There are so many connected products already in place today with many hundreds more on the h...
Digital Transformation: Preparing Cloud & IoT Security for the Age of Artificial Intelligence. As automation and artificial intelligence (AI) power solution development and delivery, many businesses need to build backend cloud capabilities. Well-poised organizations, marketing smart devices with AI and BlockChain capabilities prepare to refine compliance and regulatory capabilities in 2018. Volumes of health, financial, technical and privacy data, along with tightening compliance requirements by...
Charles Araujo is an industry analyst, internationally recognized authority on the Digital Enterprise and author of The Quantum Age of IT: Why Everything You Know About IT is About to Change. As Principal Analyst with Intellyx, he writes, speaks and advises organizations on how to navigate through this time of disruption. He is also the founder of The Institute for Digital Transformation and a sought after keynote speaker. He has been a regular contributor to both InformationWeek and CIO Insight...
Digital Transformation is much more than a buzzword. The radical shift to digital mechanisms for almost every process is evident across all industries and verticals. This is often especially true in financial services, where the legacy environment is many times unable to keep up with the rapidly shifting demands of the consumer. The constant pressure to provide complete, omnichannel delivery of customer-facing solutions to meet both regulatory and customer demands is putting enormous pressure on...
Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereal. Andrew's role at ConsenSys Enterprise is a mul...