Bug #67653 [Asn->Opn]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently
| From: | kalle@php.net | Date: | Tue, 24 Oct 2017 08:13:27 +0000 |
| Subject: | Bug #67653 [Asn->Opn]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-212244@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67653&edit=1
ID: 67653
Updated by: kalle@php.net
Reported by: yohgaki at ohgaki dot net
Summary: PASSWORD_BCRYPT truncates password longer than 72
bytes silently
-Status: Assigned
+Status: Open
Type: Bug
Package: hash related
Operating System: Irrelevant
PHP Version: 5.5
-Assigned To: yohgaki
+Assigned To:
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2014-07-19 01:58:40] yohgaki at ohgaki dot net
Description:
------------
PASSWORD_BCRYPT truncates password longer than 72 bytes silently
Test script:
---------------
[yohgaki@dev tmp]$ php -r
'var_dump(password_verify("123456789012345678901234567890123456789012345678901234567890123456789012",
password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890",
PASSWORD_DEFAULT)));'
bool(true)
[yohgaki@dev tmp]$ php -r
'var_dump(password_verify("12345678901234567890123456789012345678901234567890123456789012345678901",
password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890",
PASSWORD_DEFAULT)));'
bool(false)
Expected result:
----------------
password_hash() should raise E_NOTICE when password is too long for it.
Actual result:
--------------
Silently ignores bytes larger than 72.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67653&edit=1