Re: [DRAFT RFC] Adding Simplified Password Hashing API
| From: | Christopher Jones | Date: | Mon, 02 Jul 2012 21:21:59 +0000 |
| Subject: | Re: [DRAFT RFC] Adding Simplified Password Hashing API | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-61072@lists.php.net to get a copy of this message | ||
On 07/02/2012 01:55 PM, Anthony Ferrara wrote:
Chris,To be honest, a note next to PASSWORD_DEFAULT would be good too.Can you update the RFC (aka future documentation) and make this obvious to an end user?I just made an update (in the behavior sections). Let me know if additional clarification is needed.
I only have brainstorm thoughts on this, since I don't have a crystal ball. What if characters other than a-zA-Z0-9./ should/can be used for some PASSWORD_xxx algorithms? What if some seed is needed? What if the salt creation algorithm should be swappable due to resource usage reasons, etc? Also, do you really need a php.ini parameter? It's yet another potential way to attack a system. Chris -- christopher.jones@oracle.com http://twitter.com/#!/ghrdThe API of password_make_salt() seems restrictive. What if other options are needed in future?Can you give any examples of what options would be needed in the future, or how you would like to see the API?