Re: Re: Re: PHP Crypt functions - security audit

From: Date: Thu, 19 Sep 2013 22:10:09 +0000
Subject: Re: Re: Re: PHP Crypt functions - security audit
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message
> I think we should do this in 5.6.

+1 ... a renewed "emphasis on security" makes a good selling point when
answering the "why should I upgrade" questions. At the same time, targeting
the next minor version gives people ample time to plan/test/document
changes. Secure stream encryption settings by default is a good place to
start.

> I wonder if this is one of those rare times where an ini setting might
make sense

I'm generally anti-.ini but this sounds sensible.


Thread (25 messages)

« previous php.internals (#69236) next »