Re: Adding a simple API for secure password hashing?

From: Date: Sat, 16 Jun 2012 15:42:28 +0000
Subject: Re: Adding a simple API for secure password hashing?
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-60862@lists.php.net to get a copy of this message
On 16/06/12 15:39, Pierre Joye wrote: > However the point here is not the implementation but the APIs. > > To be honest I am not a big fan of providing such an API in the core > as no matter the default implementation, it will become obsolete soon > or later. And changing the default brings its lot of issues and BC > problems. > > That being said, it seems that we may not have the choice anyway so > having a well designed and implemented API for password (and related > or similar areas) generations may be a good thing. The generated password hash should contain versioning information (such as the $1$ for crypt), so password_verify() of later PHP versions will be able to correctly verify it, even after the default password hash changes (set an older type in php.ini if you don't want to use the new format).

« previous php.internals (#60862) next »