Re: Adding a simple API for secure password hashing?
| From: | Anthony Ferrara | Date: | Mon, 18 Jun 2012 16:54:14 +0000 |
| Subject: | Re: Adding a simple API for secure password hashing? | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-60880@lists.php.net to get a copy of this message | ||
Pierre,
> There is sadly only state-of-art-right-now password hashing methods.
> We have to keep that in mind :)
That's why the crypt() return format was designed. All of the options
that are needed to validate the hash (algorithm, cost parameter, salt,
etc) are fit right into the outputted string.
I'd suggest that's what's done here. In fact, I'd make the functions
just a thin wrapper around crypt(). Basically, just where it sets sane
defaults that we can update every minor (or major) release (to
compensate for faster servers). It handles salt generation, error
checking, etc.
Here's what I have in mind in php: https://gist.github.com/2949382
Anthony