Re: [DRAFT RFC] Adding Simplified Password Hashing API
| From: | Anthony Ferrara | Date: | Wed, 27 Jun 2012 11:24:49 +0000 |
| Subject: | Re: [DRAFT RFC] Adding Simplified Password Hashing API | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-60982@lists.php.net to get a copy of this message | ||
Simon,
> * Will the value of the constant PASSWORD_DEFAULT remain unchanged forever?
> Otherwise this lib, in my opinion, can cause big problems when trying to
> port an existing system to a newer PHP-version.
No. That's why it's a separate constant. As newer, stronger hashing
options become available, the default is designed to change over time.
I'll update the RFC to indicate such.
> * Is this a native version of phpass?
> http://www.openwall.com/phpass/
In a sense, yes. It's designed to have a dirt-simple API (similar to
yours) built in to the core.
Thanks,
Anthony