Having several open source projects of my own, and contributing to a few more, I'd like to say that I don't think you're on the right track if you're trying to get a real response with your questions here; you're basically doing the "so, have you stopped beating your wife yet" routine.
Don't believe me? Your words:
Does Django (the project as a whole) want to provide the best possible security, within reason, for its contrib.auth module?
If not, why not, and why isn't it stated prominently in the documentation?
Of course we want to provide the best possible security, within reason. But reasonable people can and do disagree on what's "within reason", and Jacob's outlined some technical hurdles regarding bcrypt which -- so far as I'm aware -- no-one in this thread has bothered to offer solutions for.
If you're genuinely interested in seeing bcrypt in Django, and have constructive suggestions on how to overcome these technical hurdles, then I'm all ears. If, on the other hand, you're just going to post passive-aggressive stuff framed to make us look like we don't really care about security, well, don't expect me or anyone else to fall all over themselves trying to help you out.
Mmm, that's not how I read Steve's questions -- I took them as honest questions about from someone who doesn't really follow the project and isn't sure where our priorities lie. We have to keep in mind that at this point a bulk of our users don't keep close track of the development process and priorities. Heck, even I have trouble keeping up some times.
At best I can say it's incredibly poorly phrased if it was trying to raise constructive points. The implication of "if you really cared about security, you'd..." just rubs me the wrong way.
I'm sorry. I'm a programmer and think in terms of `if X elif Y else Z` statements.
I admitted I might be wrong at pretty much any stage, and Jacob's response convinced me that my "rewrite bcrypt in Python" option is probably not reasonable at this point.
How could I have phrased that differently and still asked the same questions?
Comments
Having several open source projects of my own, and contributing to a few more, I'd like to say that I don't think you're on the right track if you're trying to get a real response with your questions here; you're basically doing the "so, have you stopped beating your wife yet" routine.
Don't believe me? Your words:
Does Django (the project as a whole) want to provide the best possible security, within reason, for its contrib.auth module? If not, why not, and why isn't it stated prominently in the documentation?
Of course we want to provide the best possible security, within reason. But reasonable people can and do disagree on what's "within reason", and Jacob's outlined some technical hurdles regarding bcrypt which -- so far as I'm aware -- no-one in this thread has bothered to offer solutions for.
If you're genuinely interested in seeing bcrypt in Django, and have constructive suggestions on how to overcome these technical hurdles, then I'm all ears. If, on the other hand, you're just going to post passive-aggressive stuff framed to make us look like we don't really care about security, well, don't expect me or anyone else to fall all over themselves trying to help you out.
Mmm, that's not how I read Steve's questions -- I took them as honest questions about from someone who doesn't really follow the project and isn't sure where our priorities lie. We have to keep in mind that at this point a bulk of our users don't keep close track of the development process and priorities. Heck, even I have trouble keeping up some times.
At best I can say it's incredibly poorly phrased if it was trying to raise constructive points. The implication of "if you really cared about security, you'd..." just rubs me the wrong way.
I'm sorry. I'm a programmer and think in terms of `if X elif Y else Z` statements.
I admitted I might be wrong at pretty much any stage, and Jacob's response convinced me that my "rewrite bcrypt in Python" option is probably not reasonable at this point.
How could I have phrased that differently and still asked the same questions?