Doc #66564 [ReO->Csd]: crypt() seems to silently discard input after a certain length

From: Date: Sun, 23 Aug 2015 04:52:14 +0000
Subject: Doc #66564 [ReO->Csd]: crypt() seems to silently discard input after a certain length
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-12641@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66564&edit=1 ID: 66564 Updated by: googleguy@php.net Reported by: ss23 at ss23 dot geek dot nz Summary: crypt() seems to silently discard input after a certain length -Status: Re-Opened +Status: Closed Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant Assigned To: googleguy Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2014-07-17 22:14:12] ircmaxell@php.net Automatic comment from SVN on behalf of ircmaxell Revision: http://svn.php.net/viewvc/?view=revision&revision=334309 Log: Revert 334297 and 334297, as: 1) there was no discussion prior to edits (even in #66564) 2) It is incorrect, misleading and not the overall sentiment that needs to be communicated ------------------------------------------------------------------------ [2014-06-27 15:00:47] tyrael@php.net Automatic comment from SVN on behalf of tyrael Revision: http://svn.php.net/viewvc/?view=revision&revision=333973 Log: removing the misleading sentence (reported by Solar Designer, also pointed out by Michal Špaček previously in a comment for #66564) ------------------------------------------------------------------------ [2014-03-06 23:02:35] narf at devilix dot net The currently used "Caution" block to describe this does indeed make it look like other options are better than BCrypt. And it's also kind of embarassing in the case of password_hash(), because it doesn't actually support anything else at this time. IMO, a reference to a nice description of BCrypt would be a better option and if anything should be noted in a Caution block, it is DES for trimming passwords to 9 characters. ------------------------------------------------------------------------ [2014-02-24 16:24:17] googleguy@php.net @ mail at michalspacek dot cz Your concerns are valid and duly noted. I will be updating this for clarity and bumping it down to a note instead of a caution in the param list. ------------------------------------------------------------------------ [2014-02-24 16:22:07] googleguy@php.net @ircmaxell You make a good point about misinterpretations in the documentation, but in retrospect people can misinterpret almost anything and we have very little control over how information is interpreted. The one thing I do know is that people rely on the manual to find documented behavior. I, myself, have to rely on it because I can't always remember how everything works, off the top of my head. So I'm a strong believer in documenting what it does and not how to use it. As for resolving your concerns over security, I propose we use your SO answer as a reference point for the security page in the manual and include a link to it from cryp/password_hash pages. It's informative and I think necessary to explain at length what's going on. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=66564 -- Edit this bug report at https://bugs.php.net/bug.php?id=66564&edit=1

« previous php.doc.bugs (#12641) next »