Re: [DRAFT RFC] Adding Simplified Password Hashing API
| From: | Anthony Ferrara | Date: | Tue, 03 Jul 2012 21:24:47 +0000 |
| Subject: | Re: [DRAFT RFC] Adding Simplified Password Hashing API | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-61100@lists.php.net to get a copy of this message | ||
Richard,
> There is also the case of an app that simple shouldn't run with the
> single default, but could pick and choose suitable algorithm from a
> list of defaults, while still honoring whatever is in the .ini file
> instead of going rogue with some other algorithm.
I disagree there. I think that's up to the application to decide. A
list of defaults does nothing but needlessly complicate the
implementation. How is the hash function supposed to determine which
of the list of defaults to use? Let the application layer choose, and
pass it in. The current PASSWORD_DEFAULT lives for the sole reason
that it auto-updates to indicate the most secure algorithm available.
Anthony