Re: [DRAFT RFC] Adding Simplified Password Hashing API

From: Date: Tue, 03 Jul 2012 21:24:47 +0000
Subject: Re: [DRAFT RFC] Adding Simplified Password Hashing API
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-61100@lists.php.net to get a copy of this message
Richard, > There is also the case of an app that simple shouldn't run with the > single default, but could pick and choose suitable algorithm from a > list of defaults, while still honoring whatever is in the .ini file > instead of going rogue with some other algorithm. I disagree there. I think that's up to the application to decide. A list of defaults does nothing but needlessly complicate the implementation. How is the hash function supposed to determine which of the list of defaults to use? Let the application layer choose, and pass it in. The current PASSWORD_DEFAULT lives for the sole reason that it auto-updates to indicate the most secure algorithm available. Anthony

« previous php.internals (#61100) next »