Re: [VOTE] Change crypt() behavior w/o salt
| From: | Adam Harvey | Date: | Tue, 22 Oct 2013 17:23:56 +0000 |
| Subject: | Re: [VOTE] Change crypt() behavior w/o salt | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-69771@lists.php.net to get a copy of this message | ||
On 22 October 2013 10:21, Joe Watkins <krakjoe@php.net> wrote:
> On 10/22/2013 06:11 PM, Adam Harvey wrote:
>> "Generating an insecure weak hash as no salt was given: please ensure
>> the salt parameter is specified and uses a strong hash type in order
>> to generate a cryptographically secure hash"
>
> Wonder how well it will translate ??
I tried to use the obvious scary keywords to make it obvious. If you
think the grammar on that version is convoluted, you should have seen
the first draft. :)
> Generating should be Generated, no ??
I like the present tense here — it's what crypt() IS doing, not what
it did. Makes it urgent. That said, I'm not super fussed either way.
Adam