cloudll Posted June 15, 2015 Share Posted June 15, 2015 Hey guys, this is probably a silly question but just wanted to check. This is from the PHP manual for password_needs_rehash if (password_needs_rehash($hash, PASSWORD_DEFAULT, $options)) { $newHash = password_hash($password, PASSWORD_DEFAULT, $options); $options being the cost. I understand why the cost is being used for $newhash, but why is it being used for: if (password_needs_rehash($hash, PASSWORD_DEFAULT, $options)) { Is that actually doing anything? Quote Link to comment https://forums.phpfreaks.com/topic/296831-quick-question-about-password-hashing-cost/ Share on other sites More sharing options...
QuickOldCar Posted June 15, 2015 Share Posted June 15, 2015 (edited) It's pretty much the purpose for that function, to compare if the options are the same for the hash. Depends what is in the options, it could be a different cost or algorithm. The reason it's there in the example is if you did change any options and to compare it the same. Edited June 15, 2015 by QuickOldCar Quote Link to comment https://forums.phpfreaks.com/topic/296831-quick-question-about-password-hashing-cost/#findComment-1513975 Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.