Re: crypt() should raise error without 2nd parameter

From: Date: Wed, 07 Aug 2013 11:58:32 +0000
Subject: Re: crypt() should raise error without 2nd parameter
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-68398@lists.php.net to get a copy of this message
On 07/08/13 13:00, Leigh wrote:
On 7 August 2013 11:18, Yasuo Ohgaki<yohgaki@ohgaki.net> wrote:
A user requested that crypt() should raise error without 2nd(slat) parameter. https://bugs.php.net/bug.php?id=55036 crypt() without salt generates extremely weak password hash.
The docs seem to indicate that some implementations generate their own random salt if one is not supplied? It doesn't seem right to raise a warning if it doesn't apply to _all_ cases. I do get a md5 with a salt when calling crypt, and looking at php that seems
to be the intended behavior, not something system dependant (that's done since 5.3, according to the docs). I see a problem in that it uses php_rand() to generate the salt, but the solution should be to use php_password_make_salt for creating the salt, not the warning.

« previous php.internals (#68398) next »