Req #50815 [Wfx]: Implement 323 short password hash fallback in mysqlnd
| From: | uw@php.net | Date: | Mon, 29 Oct 2012 08:10:00 +0000 |
| Subject: | Req #50815 [Wfx]: Implement 323 short password hash fallback in mysqlnd | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-174403@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=50815&edit=1
ID: 50815
Updated by: uw@php.net
Reported by: jd at cpanel dot net
Summary: Implement 323 short password hash fallback in
mysqlnd
Status: Wont fix
Type: Feature/Change Request
Package: MySQL related
Operating System: any
PHP Version: 5.3.1
Assigned To: mysql
Block user comment: N
Private report: N
New Comment:
I second Andrey: won't fix, http://sqlhack.com/ .
Previous Comments:
------------------------------------------------------------------------
[2012-10-29 08:00:54] andrey@php.net
There is no such thing as discouraging. It is about updating the credentials, so they are more
secure. Just use SET PASSWORD and hash the password again.
------------------------------------------------------------------------
[2012-10-26 17:18:09] toddr at cpanel dot net
If you want to discourage use of the short password method, couldn't you just add
a configure option to enable this and disable it by default?
------------------------------------------------------------------------
[2012-10-26 17:11:47] toddr at cpanel dot net
If all MySQL 5 versions support this hashing scheme, Aren't you kinda overriding a
user decision to enable short passwords on their MySQL server? It's also not clear
when the failure happens what the problem is.
------------------------------------------------------------------------
[2010-08-27 06:00:08] aharvey@php.net
Fix up the package to make this easier to search for.
------------------------------------------------------------------------
[2010-08-26 13:31:35] uw@php.net
We mysql guys have no plans adding old insecure password stuff to mysqlnd. As it is assigned to
us/me, I'm changing status to what shall be status from our/my perspective: won't fix.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=50815
--
Edit this bug report at https://bugs.php.net/bug.php?id=50815&edit=1