Re: crypt() BC issue
| From: | Yasuo Ohgaki | Date: | Thu, 17 Jul 2014 02:25:06 +0000 |
| Subject: | Re: crypt() BC issue | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75627@lists.php.net to get a copy of this message | ||
Hi Tjerk,
On Thu, Jul 17, 2014 at 11:09 AM, Tjerk Meesters <tjerk.meesters@gmail.com>
wrote:
> Why should
password_verify() work on a hash that wasn't
> generated with
> password_hash()? The fact that it uses
> crypt() internally should not
> leak outside of its API, imho.
password_*() is designed as crypt() wrapper and this fact is documented
since it was released.
Obsolete password hash is easy to verify with password_needs_rehash().
Developers can check password database easily with password_needs_rehash().
i.e. They don't have to parse password hash to detect obsolete hash.
Therefore, using password_*() for crypt() generated passwords makes sense.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net