Req #75388 [Com]: Argon2: Add secret/key

From: Date: Tue, 17 Oct 2017 09:34:58 +0000
Subject: Req #75388 [Com]: Argon2: Add secret/key
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211748@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75388&edit=1 ID: 75388 Comment by: daverandom@php.net Reported by: phpdoc at mail dot my1 dot info Summary: Argon2: Add secret/key Status: Feedback Type: Feature/Change Request Package: *Encryption and hash functions Operating System: Win8.1 x64 PHP Version: Next Minor Version Block user comment: N Private report: N New Comment: @requinix there is a parameter for argon2i ("Secret value K" in the linked document) which PHP does not expose. It *could* be exposed via a password hash option, however I am not qualified to have an opinion on whether it *should* be. Notably the $salt option for bcrypt was deprecated in 7 because the idea of the password_hash() API is simplicity and providing secure defaults, I don't know if this may fall into the same category of "things the user should not play with as it may make the resulting hashes less secure". I think what is being asked for is clear, whether it should be done is for people more qualified than me to discuss. I can't see any record if it being discussed as part of the original proposal. It should probably be brought up on internals. Previous Comments: ------------------------------------------------------------------------ [2017-10-16 14:03:07] requinix@php.net What are you asking for PHP to do, exactly? And is it something that can/should be easily handled in userland instead? ------------------------------------------------------------------------ [2017-10-16 12:38:55] phpdoc at mail dot my1 dot info Description: ------------ In the input/output section of the argon2 standard, there is a key/secret value https://tools.ietf.org/html/draft-irtf-cfrg-argon2-03#page-5 and it is certainly not a bad idea to use that for peppering the passwords for extra security: https://en.wikipedia.org/wiki/Pepper_(cryptography) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75388&edit=1

« previous php.bugs (#211748) next »