Bug #67653 [NEW]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently

From: Date: Sat, 19 Jul 2014 01:58:41 +0000
Subject: Bug #67653 [NEW]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186738@lists.php.net to get a copy of this message
From: yohgaki at ohgaki dot net Operating system: Irrelevant PHP version: Irrelevant Package: hash related Bug Type: Bug Bug description:PASSWORD_BCRYPT truncates password longer than 72 bytes silently Description: ------------ PASSWORD_BCRYPT truncates password longer than 72 bytes silently Test script: --------------- [yohgaki@dev tmp]$ php -r 'var_dump(password_verify("123456789012345678901234567890123456789012345678901234567890123456789012", password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890", PASSWORD_DEFAULT)));' bool(true) [yohgaki@dev tmp]$ php -r 'var_dump(password_verify("12345678901234567890123456789012345678901234567890123456789012345678901", password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890", PASSWORD_DEFAULT)));' bool(false) Expected result: ---------------- password_hash() should raise E_NOTICE when password is too long for it. Actual result: -------------- Silently ignores bytes larger than 72. -- Edit bug report at https://bugs.php.net/bug.php?id=67653&edit=1 --

« previous php.bugs (#186738) next »