Re: password_hash() deprecate salt option - thoughts?
| From: | Christoph Becker | Date: | Tue, 31 Mar 2015 19:32:50 +0000 |
| Subject: | Re: password_hash() deprecate salt option - thoughts? | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-85599@lists.php.net to get a copy of this message | ||
Nicolas Oelgart wrote:
>> On 31 Mar 2015, at 20:49, Anthony Ferrara <ircmaxell@gmail.com> wrote:
>>
>> So I'd like to hear your thoughts about raising E_DEPRECATED when the
>> salt option is specified in 7.0, with ultimately removing the option
>> in a later version.
>
> +1
>
> I'd even go as far as adding a big red warning about custom salts to the manual page.
FWIW, there is already the following note:
| Caution It is strongly recommended that you do not generate your own
| salt for this function. It will create a secure salt automatically
| for you if you do not specify one.
--
Christoph M. Becker