Re: Re: [RFC][DISCUSSION] Argon2 Password Hash
| From: | Tom Worster | Date: | Sat, 06 Aug 2016 17:08:49 +0000 |
| Subject: | Re: Re: [RFC][DISCUSSION] Argon2 Password Hash | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94886@lists.php.net to get a copy of this message | ||
On 8/5/16, 2:20 PM, "Charles R. Portwood II"
<charlesportwoodii@ethreal.net on behalf of charlesportwoodii@erianna.com>
wrote:
>It breaks the API in the interim between this RFC and a potential future
>one. The $options parameter for both password_hash and
>password_needs_rehash is optional. Making it required for one algorithm
>but not another changes the API's for both methods. The expectations
>outlined in the original password_hash RFC make the third parameter for
>tuning the algorithm, not for making the algorithm work. Without default
>values, both password_hash and password_needs_rehash would fail unless
>the costs are provided.
OK. I misunderstood what qualifies as "broken". Looks most like most
people want to set default costs right away so I'll leave it here. As for
choosing the right default values for PHP, what are the criteria?
Tom