Bug #74961 [NEW]: "Disallow non-crypto hashes in HMAC and PBKDF2" implemented poorly
From: bluebaroncanada at gmail dot com
Operating system:
PHP version: 7.2.0beta1
Package: *Encryption and hash functions
Bug Type: Bug
Bug description:"Disallow non-crypto hashes in HMAC and PBKDF2" implemented poorly
Description:
------------
Commit
https://github.com/php/php-src/commit/d89d149edf39cf4ce9ab41979f246e82510d43a5#commitcomment-23109176
is a poor implementation of its goal.
It salted the code and added a new is_crypto function which wasn't
necessary and is also insufficient.
It should provide a new hash_algos_hmac to extend
http://php.net/manual/en/function.hash-algos.php
The documentation now says "Returns FALSE when algo is unknown." and
7.2.0 Usage of non-cryptographic hash functions (adler32, crc32, crc32b,
fnv132, fnv1a32, fnv164, fnv1a64, joaat) was disabled. However it does
not say that it will return false only when providing one of these
non-cryptographic functions, which is what it actually does. There
could be future deprecation of more functions.
I suggest that either the is_crypto function is extended to the users,
but better than that, we should remove the is_crypto function and create
the hash_algos_hmac to extend the hash_algos function for the same
reason its predecessor exits and also so that we can use that function
internally to decide if the hashing algorithm should be available and
thus easily allow future deprecation and pedantic decisions on available
algorithms without further damaging the code.
The reason that this bothers me so is that phpseclib extends this
functionality and it cannot properly test with this implementation or
properly extend this functionality to pass on to its users. In the
future, if there is further deprecation, users would be treated with an
undetectable error.
This commit should be removed and rewritten.
Test script:
---------------
if (!hash_hmac('crc32', 'The quick brown fox jumped over the lazy dog.',
'secret'))
die('run for your lives');
--
Edit bug report at https://bugs.php.net/bug.php?id=74961&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74961&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74961&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74961&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74961&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74961&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74961&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74961&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74961&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74961&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74961&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74961&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74961&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74961&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74961&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74961&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74961&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74961&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74961&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74961&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74961&r=mysqlcfg
Thread (10 messages)
- bluebaroncanada at gmail dot com