use password_ok() instead of calling crypt()