Req #75388 [Com]: Argon2: Add secret/key
| From: | daverandom@php.net | Date: | Tue, 17 Oct 2017 09:34:58 +0000 |
| Subject: | Req #75388 [Com]: Argon2: Add secret/key | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-211748@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75388&edit=1
ID: 75388
Comment by: daverandom@php.net
Reported by: phpdoc at mail dot my1 dot info
Summary: Argon2: Add secret/key
Status: Feedback
Type: Feature/Change Request
Package: *Encryption and hash functions
Operating System: Win8.1 x64
PHP Version: Next Minor Version
Block user comment: N
Private report: N
New Comment:
@requinix there is a parameter for argon2i ("Secret value K" in the linked document) which
PHP does not expose. It *could* be exposed via a password hash option, however I am not qualified to
have an opinion on whether it *should* be.
Notably the $salt option for bcrypt was deprecated in 7 because the idea of the password_hash() API
is simplicity and providing secure defaults, I don't know if this may fall into the same
category of "things the user should not play with as it may make the resulting hashes less
secure".
I think what is being asked for is clear, whether it should be done is for people more qualified
than me to discuss. I can't see any record if it being discussed as part of the original
proposal. It should probably be brought up on internals.
Previous Comments:
------------------------------------------------------------------------
[2017-10-16 14:03:07] requinix@php.net
What are you asking for PHP to do, exactly? And is it something that can/should be easily handled in
userland instead?
------------------------------------------------------------------------
[2017-10-16 12:38:55] phpdoc at mail dot my1 dot info
Description:
------------
In the input/output section of the argon2 standard, there is a key/secret value
https://tools.ietf.org/html/draft-irtf-cfrg-argon2-03#page-5
and it is certainly not a bad idea to use that for peppering the passwords for extra security:
https://en.wikipedia.org/wiki/Pepper_(cryptography)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75388&edit=1