From: vincent.fourmond@9online.fr Date: 2006-12-05T22:45:21+09:00 Subject: Re: String#crypt first 8 characters

----- Original Message -----
From: Patrick Plattes
Date: Tuesday, December 5, 2006 2:09 pm
Subject: String#crypt first 8 characters
To: ruby-talk@ruby-lang.org (ruby-talk ML)
> irb(main):022:0> "1234567".crypt('aa')
> => "aaOK9MRbwVNmQ"
> irb(main):023:0> "12345678".crypt('aa')
> => "aaNN3X.PL2piw"
> irb(main):024:0> "123456789".crypt('aa')
> => "aaNN3X.PL2piw"
>
> If it is a feature not a bug, it should not be an undocumented
> feature
> ;-) . ruby-doc.org doesn't told me about this behaviour.

String.crypt is a wrapper around Unix standard C function crypt, used to encrypt passwords. From man crypt,

By taking the lowest 7 bits of each of the first eight characters of the key, a 56-bit key
is obtained. This 56-bit key is used to encrypt repeatedly a constant string (usually a
string consisting of all zeros). The returned value points to the encrypted password, a
series of 13 printable ASCII characters (the first two characters represent the salt
itself). The return value points to static data whose content is overwritten by each
call.

There goes your explanation. But that should be documented, I agree with you. My opinion is that you should use crypt if you plan to interface somehow with Unix password database. If you want one way cryptography, try MD5:

require 'digest/md5'
digest = Digest::MD5.hexdigest("Hello World\n")
puts digest

Cheers,

Vince