Doc #63549 [NEW]: Wrong commentary
| From: | varnavruz at gmail dot com | Date: | Sat, 17 Nov 2012 15:35:29 +0000 |
| Subject: | Doc #63549 [NEW]: Wrong commentary | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-9174@lists.php.net to get a copy of this message | ||
From: varnavruz at gmail dot com
Operating system:
PHP version: Irrelevant
Package: Documentation problem
Bug Type: Documentation Problem
Bug description:Wrong commentary
Description:
------------
---
From manual page:
http://www.php.net/function.crypt#refsect1-function.crypt-
description
---
Page says:
Please refer to » this document for full details of the security fix, but
to
summarise, developers targeting only PHP 5.3.7 and later should use "$2y$"
in
preference to "$2a$".
But linked document (http://www.php.net/security/crypt_blowfish.php) says:
if the app prefers security and correctness over backwards compatibility,
no
action is needed - just upgrade to new PHP and use its new behavior (with
$2a$).
However, if an app install admin truly prefers backwards compatibility over
security, and the problem is seen on the specific install ... using $2y$ on
newly set passwords.
So, this means that manual recommends backwards compatibility over
security, not
security and correctness over backwards compatibility for developers
targeting
only PHP 5.3.7 and later.
Why developers targeting only PHP 5.3.7 and later shall worry about
insecure
backwards compatibility?
Expected result:
----------------
Please remove the wrong recommendation to use $2y$ over $2a$
--
Edit bug report at https://bugs.php.net/bug.php?id=63549&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=63549&r=trysnapshot54
Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=63549&r=trysnapshot53
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=63549&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=63549&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=63549&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=63549&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=63549&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=63549&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=63549&r=support
Expected behavior: https://bugs.php.net/fix.php?id=63549&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=63549&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=63549&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=63549&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=63549&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=63549&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=63549&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=63549&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=63549&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=63549&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=63549&r=mysqlcfg