Re: Adding a simple API for secure password hashing?

From: Date: Mon, 18 Jun 2012 16:03:47 +0000
Subject: Re: Adding a simple API for secure password hashing?
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-60879@lists.php.net to get a copy of this message
On 18.06.2012, at 19:42, Pierre Joye wrote: >>>> It is BSD-licensed, so we can easily bundle it with PHP >>> >>> Maybe nice to have in pecl.' >> >> Sure, that's an option, but pecl won't help php to have default >> "state-of-art" password hashing toolset ;) > > There is sadly only state-of-art-right-now password hashing methods. > We have to keep that in mind :) Sure. but SCrypt is tuneable. One can increase both CPU and RAM complexity and CPU complexity is set as function of time. Which means, that if one upgrades CPU in his server, while leaving settings the same complexity will increase automatically. This feature makes it future-proof to some degree. Well… until quantum computers become ubiquitous ;)

« previous php.internals (#60879) next »