Re: [PHP-DEV] [VOTE] Increasing the default BCrypt cost

2023-09-22 Thread Remi Collet
more results on ARM: RK3399 - Cortex-A7x Cost 10: 10.694221 total (0.106942 per hash) Cost 11: 21.360409 total (0.213604 per hash) Cost 12: 42.692786 total (0.426928 per hash) RK3399 - Cortex-A5x Cost 10: 15.146773 total (0.151468 per hash) Cost 11: 30.272059 total (0.302721 per hash) Cost 12:

Re: [PHP-DEV] [VOTE] Increasing the default BCrypt cost

2023-09-22 Thread Craig Francis
On 22 Sep 2023, at 08:04, Nicolas Grekas wrote: > For the record, I voted for 11 because I think it's nicer to end users (I > guess many don't know they could have a potential DoS vector via password > submissions), and also because it's going to be easy to raise again in > 8.5/9.0. +1 I can

Re: [PHP-DEV] [VOTE] Increasing the default BCrypt cost

2023-09-22 Thread Tim Düsterhus
Hi On 9/22/23 09:04, Nicolas Grekas wrote: For the record, I voted for 11 because I think it's nicer to end users (I guess many don't know they could have a potential DoS vector via password submissions), and also because it's going to be easy to raise again in 8.5/9.0. I was wondering if you c

Re: [PHP-DEV] [RFC] [Discussion] XML_OPTION_PARSE_HUGE

2023-09-22 Thread Niels Dossche
Hi Larry On 22/09/2023 01:05, Larry Garfield wrote: > On Thu, Sep 21, 2023, at 9:26 PM, Niels Dossche wrote: >> Hi internals >> >> I'd like to put a new RFC under discussion: >> https://wiki.php.net/rfc/xml_option_parse_huge >> >> Kind regards >> Niels > > Seems reasonable to me at first glance.

Re: [PHP-DEV] [RFC] [Discussion] XML_OPTION_PARSE_HUGE

2023-09-22 Thread Niels Dossche
Hi Aleksander On 22/09/2023 07:51, Aleksander Machniak wrote: > On 21.09.2023 23:26, Niels Dossche wrote: >> I'd like to put a new RFC under discussion: >> https://wiki.php.net/rfc/xml_option_parse_huge > > Looking at LIBXML_PARSEHUGE at > https://www.php.net/manual/en/libxml.constants.php > >

Re: [PHP-DEV] [VOTE] Increasing the default BCrypt cost

2023-09-22 Thread Nicolas Grekas
I just opened the vote for the "Increasing the default BCrypt cost" RFC. > The RFC contains a two votes, one primary vote that requires a 2/3 > majority to pass and a secondary vote deciding on the new costs with a > simple majority. Voting runs 2 weeks until 2023-10-05 17:45 UTC. > > Please find t