Re: Adding a simple API for secure password hashing?
| From: | Ángel González | Date: | Sat, 16 Jun 2012 15:42:28 +0000 |
| Subject: | Re: Adding a simple API for secure password hashing? | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-60862@lists.php.net to get a copy of this message | ||
On 16/06/12 15:39, Pierre Joye wrote:
> However the point here is not the implementation but the APIs.
>
> To be honest I am not a big fan of providing such an API in the core
> as no matter the default implementation, it will become obsolete soon
> or later. And changing the default brings its lot of issues and BC
> problems.
>
> That being said, it seems that we may not have the choice anyway so
> having a well designed and implemented API for password (and related
> or similar areas) generations may be a good thing.
The generated password hash should contain versioning information (such
as the $1$ for crypt), so password_verify() of later PHP versions will
be able
to correctly verify it, even after the default password hash changes
(set an older
type in php.ini if you don't want to use the new format).