微信公众号搜"智元新知"关注
微信扫一扫可直接关注哦!

php – password_hash中的成本选项是什么

PHP手册中,有很多例子在password_hash中使用cost
一些例子用来计算好的成本

<?PHP
/**
* This code will benchmark your server to determine how high of a cost you can
* afford. You want to set the highest cost that you can without slowing down
* you server too much. 8-10 is a good baseline, and more is good if your servers
* are fast enough. The code below aims for ≤ 50 milliseconds stretching time,
 * which is a good baseline for systems handling interactive logins.
 */
$tiMetarget = 0.05; // 50 milliseconds 

$cost = 8;
do {
 $cost++;
 $start = microtime(true);
 password_hash("test", PASSWORD_BCRYPT, ["cost" => $cost]);
 $end = microtime(true);
} while (($end - $start) < $tiMetarget);

echo "Appropriate Cost Found: " . $cost . "\n";
?>

成本代表什么?

解决方法:

wikipedia开始:

The cost parameter specifies a key expansion iteration count as a
power of two, which is an input to the crypt algorithm.

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。

相关推荐