Req #75224 [Opn->Csd]: Allow for argon2id in password_hash
| From: | cmb@php.net | Date: | Mon, 09 Sep 2019 16:46:22 +0000 |
| Subject: | Req #75224 [Opn->Csd]: Allow for argon2id in password_hash | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222665@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75224&edit=1
ID: 75224
Updated by: cmb@php.net
Reported by: phpdoc at mail dot my1 dot info
Summary: Allow for argon2id in password_hash
-Status: Open
+Status: Closed
Type: Feature/Change Request
Package: *Encryption and hash functions
Operating System: Win8.1 x64
PHP Version: Next Minor Version
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
argon2id is supported as of PHP 7.3.0.
Previous Comments:
------------------------------------------------------------------------
[2017-09-18 13:46:14] phpdoc at mail dot my1 dot info
Description:
------------
argon2i is pretty nice for password hashing, true but it has some problems with memory/computation
tradeoffs, wouldnt it be epic to have argon2id in the next version (as PHP7.2 is already frozen) to
have a hybrid which goes both against side channels and tradeoff attacks?
in fact the ietf draft for argon2 recommends using argon2id as default.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75224&edit=1