Should I validate a username and pass word by searching for both in the SQL table Or Should I find the username then match the pass word with a PHP if statement?
- SELECT * FROM table WHERE username = $username AND password =$password
- SELECT * FROM table WHERE username = $username...- if ($row[password] == $password) { do stuff }
Which method Is more secure and efficient?
 
     
     
     
    