1. 云栖社区>
  2. PHP教程>
  3. 正文

Evert Pot: The problem with password_hash

作者:用户 来源:互联网 时间:2017-12-01 17:14:53

Evert Pot: The problem with password_hash - 摘要: 本文讲的是Evert Pot: The problem with password_hash, Evert Pothas shared some of his thoughts aboutwhy he has a problem with password_hash (and friends). His thoughts are i

Evert Pothas shared some of his thoughts aboutwhy he has a problem with password_hash (and friends). His thoughts are initially about this particular feature but they're actually wider than that.

The initial introduction and rfc for these functions made me uneasy, and I felt like a lone voice against many in that I thought something bad was happening. I felt that they should not be added to the PHP engine. I think that we should not extend the PHP engine, when it's possible to write the same API in userland, or there are significant benefits to do it in PHP, such as performance. Since the heavy lifting of the password functions is done by underlying libraries that are already exposed to userland-PHP, it didn't make sense to me to expose it as well in the core.

He includes a list of things he sees as drawbacks for new C-based functionality in PHP including the fact that it extends the "PHP specification" and forces other projects to implement it (like HHVM). He does include a few positives, though, such as the increased visibility and legitimacy, but still thinks they don't outweigh the negatives.

以上是云栖社区小编为您精心准备的的内容,在云栖社区的博客、问答、公众号、人物、课程等栏目也有的相关内容,欢迎继续使用右上角搜索按钮进行搜索,以便于您获取更多的相关知识。