Home  |  Linux  | Mysql  | PHP  | XML
From:Pierre Joye Date:Mon Jul 21 01:34:10 2008
Subject:Re: new crypt implementation, latest DES version used, blowfish support
Hi,

On Sun, Jul 20, 2008 at 5:55 PM, Pierre Joye <pierre.php@gmail.com> wrote:

> What do you think about enabling Blowfish and extended DES for the
> unix as well (when the libc does not have them obviously)?

I discussed this patch and addition with Stefan Esser this morning. He
also likes the idea of enabling both when necessary for all platforms.

One thing I will have to change in my patch is the blowfish salt
generation. Apparently some users were smart enough to store generated
password in the DB without having used a salt. As it is not portable,
it may break an app running on the same host. I'll try to update the
documentation with some recommendations (there is really crazy things
being done with crypt...).

Cheers,
--
Pierre

http://blog.thepimp.net | http://www.libgd.org
Navigate in group php.internals.win at sever news.php.net
Previous Next




  
© No Copyright
You are free to use Anything
Site Maintained by Zareef Ahmed
Powered By PHP Consultants