Re: RFC proposal to deprecate crypt()

From: Date: Sun, 20 Feb 2022 07:10:57 +0000
Subject: Re: RFC proposal to deprecate crypt()
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-117073@lists.php.net to get a copy of this message
Hi! On 2/19/22 6:03 PM, steve@tobtu.com wrote:
crypt() should be deprecate because it can be used to create bad password hashes:
I don't think it's a good reason for deprecating functions. A lot of functions, if used incorrectly, could produce bad results, it's not the reason to not use them correctly.
Since password_verify() and password_needs_rehash() already supports hashes created with crypt(), the only thing needed to do is remove crypt().
Removing it would cause serious BC issues with no practical gain. -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#117073) next »