Re: crypt() BC issue

From: Date: Wed, 16 Jul 2014 01:12:34 +0000
Subject: Re: crypt() BC issue
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-75571@lists.php.net to get a copy of this message
On 16 Jul 2014, at 01:46, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > - Developer may use larger rounds and store updated hash when > user is authenticated with old PHP. > - Developer may ask users to reset password if password hash has > to fewer rounds than 1000 (i.e. outdated hash) with new PHP. Wait, doesn’t that mean you’re unable to verify passwords now? -- Andrea Faulds http://ajf.me/

« previous php.internals (#75571) next »