Re: [PHP-DEV] Re: crypt() BC issue

2014-07-19 Thread Yasuo Ohgaki
Hi Nikita, On Sat, Jul 19, 2014 at 2:46 PM, Nikita Popov wrote: > I'm against adding this notice to password_hash. This will require all > applications to ensure that passwords are shorter than 72 chars. I don't > think that's a good idea. Generally speaking, it would not be serious issue. 72

Re: [PHP-DEV] Re: crypt() BC issue

2014-07-19 Thread Andrey Andreev
On Jul 19, 2014 11:45 AM, "Yasuo Ohgaki" wrote: > > Hi Nikita, > > On Sat, Jul 19, 2014 at 2:46 PM, Nikita Popov wrote: > > > I'm against adding this notice to password_hash. This will require all > > applications to ensure that passwords are shorter than 72 chars. I don't > > think that's a good

Re: [PHP-DEV] crypt() BC issue

2014-07-19 Thread Anthony Ferrara
Yasuo > I'll suggest users to use SHA512 raw output as password to > remove 72 chars limitation if it is needed. Then you either misunderstood what I was saying, or completely ignored it. > Raising E_NOTICE for too long password for PASSWORD_BCRYPT > makes sense. I'll add it later. > > https://b

[PHP-DEV] [VOTE][RFC] Name of Next Release of PHP

2014-07-19 Thread Andrea Faulds
Good evening, It is finally time to settle this matter once and for all. What shall be the name of the next release of PHP: PHP 6 or PHP 7? The poll is now open: https://wiki.php.net/rfc/php6#vote Voting shall end in a week’s time on 2014-07-27. Thanks! -- Andrea Faulds http://ajf.me/ --

[PHP-DEV] Re: 5.3 final release

2014-07-19 Thread Stas Malyshev
Hi! According to PHP 5.3 EOL RFC, we've now a month past official EOL date, but we've planned to make one final release incorporating most important fixes from upper branches since the last 5.3 release. To help with that, I've created a pull here: https://github.com/php/php-src/pull/730 That lis

Re: [PHP-DEV] crypt() BC issue

2014-07-19 Thread Yasuo Ohgaki
Hi Anthony, On Sun, Jul 20, 2014 at 12:27 AM, Anthony Ferrara wrote: > > I'll suggest users to use SHA512 raw output as password to > > remove 72 chars limitation if it is needed. > > Then you either misunderstood what I was saying, or completely ignored it. > SHA512 raw output may truncate byt

Re: [PHP-DEV] [VOTE][RFC] Name of Next Release of PHP

2014-07-19 Thread Zeev Suraski
Andrea, Please stop (pause) this vote. I told you I want to represent the cars for PHP 7, and I told you it'll take a bit of time - and that was before my city became under rocket fire.. There's no rush for this RFC - it can easily wait a week or even a few more weeks if necessary. I'll try to

RE: [PHP-DEV] [VOTE][RFC] Name of Next Release of PHP

2014-07-19 Thread Zeev Suraski
I took the time to rewrite the case for PHP 7. It's a complete rewrite written by someone who actually believes that this is the right choice for us to pick :) I'm sure people will have comments and may want to both improve the case for 6 and 7 - so I do recommend we give it another extra week of