Re: [DRAFT RFC] Adding Simplified Password Hashing API

From: Date: Mon, 02 Jul 2012 19:57:52 +0000
Subject: Re: [DRAFT RFC] Adding Simplified Password Hashing API
References: 1 2 3 4 5 6 7 8 9 10 11 12  Groups: php.internals 
Request: Send a blank email to internals+get-61069@lists.php.net to get a copy of this message
On 06/27/2012 07:16 AM, Anthony Ferrara wrote:
Arvids, On Wed, Jun 27, 2012 at 9:23 AM, Arvids Godjuks <arvids.godjuks@gmail.com> wrote:
Hello. I personally think that using PASSWORD_DEFAULT for algorythm by default is a bad idea. This should be defined by user in the code. Even worse if it is defined by .ini setting - deploy to a remote server and realize that there is a different .ini default that messes up everything. Lessons learned in the past are forgetten fast?
It wouldn't mess up anything. All it would do is change the algorithm used by the library when creating new passwords. Existing ones will still validate. The new ones will validate on the old server as long as that algorithm is supported (could be an issue in a mixed environment where there are servers using an older version without support for the new method in crypt())...
Hi Anthony, Can you update the RFC (aka future documentation) and make this obvious to an end user? Chris -- christopher.jones@oracle.com http://twitter.com/#!/ghrd

« previous php.internals (#61069) next »