Re: Adding a simple API for secure password hashing?

From: Date: Mon, 18 Jun 2012 16:54:14 +0000
Subject: Re: Adding a simple API for secure password hashing?
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-60880@lists.php.net to get a copy of this message
Pierre, > There is sadly only state-of-art-right-now password hashing methods. > We have to keep that in mind :) That's why the crypt() return format was designed. All of the options that are needed to validate the hash (algorithm, cost parameter, salt, etc) are fit right into the outputted string. I'd suggest that's what's done here. In fact, I'd make the functions just a thin wrapper around crypt(). Basically, just where it sets sane defaults that we can update every minor (or major) release (to compensate for faster servers). It handles salt generation, error checking, etc. Here's what I have in mind in php: https://gist.github.com/2949382 Anthony

« previous php.internals (#60880) next »