Re: internals Digest 3 Feb 2017 23:56:52 -0000 Issue 4435
| From: | Andrey Andreev | Date: | Sat, 04 Feb 2017 21:19:11 +0000 |
| Subject: | Re: internals Digest 3 Feb 2017 23:56:52 -0000 Issue 4435 | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-98200@lists.php.net to get a copy of this message | ||
Hi again,
On Sat, Feb 4, 2017 at 10:27 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Hi Andrey,
>
> On Sun, Feb 5, 2017 at 3:21 AM, Andrey Andreev <narf@devilix.net> wrote:
>
>> Have *you* read anything else in the RFC?
>>
>> The reason why its authors have to recommend salt usage is because it is
>> *otherwise the only optional part of the algorithm*.
>>
>
> Nonsense. You misread the RFC and my mail.
> Who stores plain text password in db now a days?
> It should be crypt() or hash_password().
>
> The RFC obviously recommends salt for improved security.
> It's even clear from your misunderstood usage, plain text password ikm.
>
>
Speaking of nonsense, I need you to point out where have I ever suggested
using passwords - hashed or not - as IKM.
At this point it's not even about misunderstandings. You are literally
making things up.
Cheers,
Andrey.