Doc #66564 [ReO->Csd]: crypt() seems to silently discard input after a certain length
| From: | googleguy@php.net | Date: | Sun, 23 Aug 2015 04:52:14 +0000 |
| Subject: | Doc #66564 [ReO->Csd]: crypt() seems to silently discard input after a certain length | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12641@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66564&edit=1
ID: 66564
Updated by: googleguy@php.net
Reported by: ss23 at ss23 dot geek dot nz
Summary: crypt() seems to silently discard input after a
certain length
-Status: Re-Opened
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
Assigned To: googleguy
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2014-07-17 22:14:12] ircmaxell@php.net
Automatic comment from SVN on behalf of ircmaxell
Revision: http://svn.php.net/viewvc/?view=revision&revision=334309
Log: Revert 334297 and 334297, as:
1) there was no discussion prior to edits (even in #66564)
2) It is incorrect, misleading and not the overall sentiment that needs to be communicated
------------------------------------------------------------------------
[2014-06-27 15:00:47] tyrael@php.net
Automatic comment from SVN on behalf of tyrael
Revision: http://svn.php.net/viewvc/?view=revision&revision=333973
Log: removing the misleading sentence (reported by Solar Designer, also pointed out by Michal
Å paÄek previously in a comment for #66564)
------------------------------------------------------------------------
[2014-03-06 23:02:35] narf at devilix dot net
The currently used "Caution" block to describe this does indeed make it look like other
options are better than BCrypt. And it's also kind of embarassing in the case of
password_hash(), because it doesn't actually support anything else at this time.
IMO, a reference to a nice description of BCrypt would be a better option and if anything should be
noted in a Caution block, it is DES for trimming passwords to 9 characters.
------------------------------------------------------------------------
[2014-02-24 16:24:17] googleguy@php.net
@ mail at michalspacek dot cz
Your concerns are valid and duly noted.
I will be updating this for clarity and bumping it down to a note instead of a caution in the param
list.
------------------------------------------------------------------------
[2014-02-24 16:22:07] googleguy@php.net
@ircmaxell
You make a good point about misinterpretations in the documentation, but in retrospect people can
misinterpret almost anything and we have very little control over how information is interpreted.
The one thing I do know is that people rely on the manual to find documented behavior. I, myself,
have to rely on it because I can't always remember how everything works, off the top of my
head. So I'm a strong believer in documenting what it does and not how to use it.
As for resolving your concerns over security, I propose we use your SO answer as a reference point
for the security page in the manual and include a link to it from cryp/password_hash pages.
It's informative and I think necessary to explain at length what's going on.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=66564
--
Edit this bug report at https://bugs.php.net/bug.php?id=66564&edit=1