Doc #63549 [NEW]: Wrong commentary

From: Date: Sat, 17 Nov 2012 15:35:29 +0000
Subject: Doc #63549 [NEW]: Wrong commentary
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-9174@lists.php.net to get a copy of this message
From: varnavruz at gmail dot com Operating system: PHP version: Irrelevant Package: Documentation problem Bug Type: Documentation Problem Bug description:Wrong commentary Description: ------------ --- From manual page: http://www.php.net/function.crypt#refsect1-function.crypt- description --- Page says: Please refer to » this document for full details of the security fix, but to summarise, developers targeting only PHP 5.3.7 and later should use "$2y$" in preference to "$2a$". But linked document (http://www.php.net/security/crypt_blowfish.php) says: if the app prefers security and correctness over backwards compatibility, no action is needed - just upgrade to new PHP and use its new behavior (with $2a$). However, if an app install admin truly prefers backwards compatibility over security, and the problem is seen on the specific install ... using $2y$ on newly set passwords. So, this means that manual recommends backwards compatibility over security, not security and correctness over backwards compatibility for developers targeting only PHP 5.3.7 and later. Why developers targeting only PHP 5.3.7 and later shall worry about insecure backwards compatibility? Expected result: ---------------- Please remove the wrong recommendation to use $2y$ over $2a$ -- Edit bug report at https://bugs.php.net/bug.php?id=63549&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=63549&r=trysnapshot54 Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=63549&r=trysnapshot53 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=63549&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=63549&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=63549&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=63549&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=63549&r=needscript Try newer version: https://bugs.php.net/fix.php?id=63549&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=63549&r=support Expected behavior: https://bugs.php.net/fix.php?id=63549&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=63549&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=63549&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=63549&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=63549&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=63549&r=dst IIS Stability: https://bugs.php.net/fix.php?id=63549&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=63549&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=63549&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=63549&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=63549&r=mysqlcfg

« previous php.doc.bugs (#9174) next »