Bug #67653 [NEW]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently
| From: | yohgaki at ohgaki dot net | Date: | Sat, 19 Jul 2014 01:58:41 +0000 |
| Subject: | Bug #67653 [NEW]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-186738@lists.php.net to get a copy of this message | ||
From: yohgaki at ohgaki dot net
Operating system: Irrelevant
PHP version: Irrelevant
Package: hash related
Bug Type: Bug
Bug description:PASSWORD_BCRYPT truncates password longer than 72 bytes silently
Description:
------------
PASSWORD_BCRYPT truncates password longer than 72 bytes silently
Test script:
---------------
[yohgaki@dev tmp]$ php -r
'var_dump(password_verify("123456789012345678901234567890123456789012345678901234567890123456789012",
password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890",
PASSWORD_DEFAULT)));'
bool(true)
[yohgaki@dev tmp]$ php -r
'var_dump(password_verify("12345678901234567890123456789012345678901234567890123456789012345678901",
password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890",
PASSWORD_DEFAULT)));'
bool(false)
Expected result:
----------------
password_hash() should raise E_NOTICE when password is too long for it.
Actual result:
--------------
Silently ignores bytes larger than 72.
--
Edit bug report at https://bugs.php.net/bug.php?id=67653&edit=1
--