Re: [VOTE] Increasing the default BCrypt cost
| From: | Craig Francis | Date: | Fri, 13 Oct 2023 01:26:53 +0000 |
| Subject: | Re: [VOTE] Increasing the default BCrypt cost | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-121292@lists.php.net to get a copy of this message | ||
On 12 Oct 2023, at 19:50, Jordan LeDoux <jordan.ledoux@gmail.com> wrote:
> That's not how voting works in the PHP project. The 2/3 is for whether or not the feature
> change should be made at all. In the case that there are multiple implementations or variations, the
> choice between those is usually simple majority. People can and do vote no on the main 2/3 vote if
> they feel that only one of the implementations/variations are acceptable.
Isn't it odd, if I had a vote, I'd have changed my first one to no if it meant jumping the
default from 10 to 12 (ref shared hosting, and low powered servers)... doesn't matter though,
when I finally get around to updating WordPress to use password_hash(), I'll probably set the
cost rather than using the default (weird how that happens, some people think they are making things
more secure, but end up making things worse).
Craig