[wp-trac] [WordPress Trac] #25816: Use a CSPRNG when generating passwords

WordPress Trac noreply at wordpress.org
Mon Nov 4 14:44:41 UTC 2013


#25816: Use a CSPRNG when generating passwords
-------------------------+------------------------------
 Reporter:  rmccue       |       Owner:
     Type:  enhancement  |      Status:  new
 Priority:  normal       |   Milestone:  Awaiting Review
Component:  Security     |     Version:
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------------

Comment (by rmccue):

 Solar Designer also points out
 ([https://twitter.com/solardiz/status/397371837610729472 1],
 [https://twitter.com/solardiz/status/397372102250352640 2],
 [https://twitter.com/solardiz/status/397372570993184768 3]) that we have
 [http://core.trac.wordpress.org/browser/trunk/src/wp-includes/class-
 phpass.php#L55 an implementation in PHPass] that we can borrow from, as
 well as [https://github.com/therealmik/passgen-
 fun/blob/master/randompw.php this implementation designed for DokuWiki].

--
Ticket URL: <http://core.trac.wordpress.org/ticket/25816#comment:2>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list