Re: RFC proposal to deprecate crypt()
| From: | Stanislav Malyshev | Date: | Sun, 20 Feb 2022 07:10:57 +0000 |
| Subject: | Re: RFC proposal to deprecate crypt() | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-117073@lists.php.net to get a copy of this message | ||
Hi!
On 2/19/22 6:03 PM, steve@tobtu.com wrote:
crypt() should be deprecate because it can be used to create bad password hashes:I don't think it's a good reason for deprecating functions. A lot of functions, if used incorrectly, could produce bad results, it's not the reason to not use them correctly.
Since password_verify() and password_needs_rehash() already supports hashes created with crypt(), the only thing needed to do is remove crypt().Removing it would cause serious BC issues with no practical gain. -- Stas Malyshev smalyshev@gmail.com