Re: [VOTE] Increasing the default BCrypt cost

From: Date: Fri, 13 Oct 2023 01:26:53 +0000
Subject: Re: [VOTE] Increasing the default BCrypt cost
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-121292@lists.php.net to get a copy of this message
On 12 Oct 2023, at 19:50, Jordan LeDoux <jordan.ledoux@gmail.com> wrote: > That's not how voting works in the PHP project. The 2/3 is for whether or not the feature > change should be made at all. In the case that there are multiple implementations or variations, the > choice between those is usually simple majority. People can and do vote no on the main 2/3 vote if > they feel that only one of the implementations/variations are acceptable. Isn't it odd, if I had a vote, I'd have changed my first one to no if it meant jumping the default from 10 to 12 (ref shared hosting, and low powered servers)... doesn't matter though, when I finally get around to updating WordPress to use password_hash(), I'll probably set the cost rather than using the default (weird how that happens, some people think they are making things more secure, but end up making things worse). Craig

« previous php.internals (#121292) next »