Re: [VOTE] Change crypt() behavior w/o salt
| From: | Andrea Faulds | Date: | Tue, 22 Oct 2013 09:58:48 +0000 |
| Subject: | Re: [VOTE] Change crypt() behavior w/o salt | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-69751@lists.php.net to get a copy of this message | ||
On 22/10/2013 07:10, Yasuo Ohgaki wrote:
Hi all, Any comments patch for this RFC? Better E_NOTICE message is welcome.I'm a native English speaker, how about "Calling crypt() without giving a salt will not produce strong password hashes."? It doesn't necessarily say you will produce a strong hash with it (other factors are at play), but it does say that you can't without it. Perhaps "secure" might be better than "strong". Just my 2 pence. -- Andrea Faulds http://ajf.me/