Re: crypt() BC issue
| From: | Andrea Faulds | Date: | Wed, 16 Jul 2014 01:12:34 +0000 |
| Subject: | Re: crypt() BC issue | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75571@lists.php.net to get a copy of this message | ||
On 16 Jul 2014, at 01:46, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> - Developer may use larger rounds and store updated hash when
> user is authenticated with old PHP.
> - Developer may ask users to reset password if password hash has
> to fewer rounds than 1000 (i.e. outdated hash) with new PHP.
Wait, doesn’t that mean you’re unable to verify passwords now?
--
Andrea Faulds
http://ajf.me/