[wp-trac] [WordPress Trac] #21022: Use bcrypt for password hashing; updating old hashes

WordPress Trac noreply at wordpress.org
Wed Feb 19 16:26:58 UTC 2025


#21022: Use bcrypt for password hashing; updating old hashes
-------------------------------------------------+-------------------------
 Reporter:  th23                                 |       Owner:
                                                 |  johnbillion
     Type:  enhancement                          |      Status:  reopened
 Priority:  normal                               |   Milestone:  6.8
Component:  Security                             |     Version:  3.4
 Severity:  normal                               |  Resolution:
 Keywords:  has-patch needs-testing has-unit-    |     Focuses:
  tests has-dev-note                             |
-------------------------------------------------+-------------------------

Comment (by stgoos):

 Replying to [comment:227 jorbin]:
 > Additionally, as long as password resets work, people will **not** be
 locked out of their site.

 **Exactly!!**

 And the bigger a site is, the higher the chances that the webmaster
 actually tests new versions on a staging environment first. I reckon that
 rollback scenarios would mainly occur with smaller sites that don't test
 new versions upfront.

 Don't let non-working passwords after a rollback back to 6.7 (or earlier)
 be a showstopper for deploying the much-anticipated improvement to the
 password hashing method.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/21022#comment:228>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list