Re: RFC proposal to deprecate crypt()

From: Date: Mon, 21 Feb 2022 17:37:25 +0000
Subject: Re: RFC proposal to deprecate crypt()
References: 1 2 3 4 5 6 7 8 9  Groups: php.internals 
Request: Send a blank email to internals+get-117108@lists.php.net to get a copy of this message
On 21/02/2022 16:43, steve@tobtu.com wrote:
If crypt() is removed, you can still use password_verify() to verify all the password hashes created by crypt(). The only thing you lose is creating those bad password hashes. Which can be done in userland because most people aren't changing their passwords daily. So it will run that slow userland code infrequently.
What "slow userland code"? Is there an implementation of the legacy crypt hashing function in pure PHP out there somewhere? I certainly wouldn't be confident writing one. Regards, -- Rowan Tommins [IMSoP]

« previous php.internals (#117108) next »