Bug #67653 [Asn->Opn]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently

From: Date: Tue, 24 Oct 2017 08:13:27 +0000
Subject: Bug #67653 [Asn->Opn]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-212244@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67653&edit=1 ID: 67653 Updated by: kalle@php.net Reported by: yohgaki at ohgaki dot net Summary: PASSWORD_BCRYPT truncates password longer than 72 bytes silently -Status: Assigned +Status: Open Type: Bug Package: hash related Operating System: Irrelevant PHP Version: 5.5 -Assigned To: yohgaki +Assigned To: Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2014-07-19 01:58:40] yohgaki at ohgaki dot net Description: ------------ PASSWORD_BCRYPT truncates password longer than 72 bytes silently Test script: --------------- [yohgaki@dev tmp]$ php -r 'var_dump(password_verify("123456789012345678901234567890123456789012345678901234567890123456789012", password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890", PASSWORD_DEFAULT)));' bool(true) [yohgaki@dev tmp]$ php -r 'var_dump(password_verify("12345678901234567890123456789012345678901234567890123456789012345678901", password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890", PASSWORD_DEFAULT)));' bool(false) Expected result: ---------------- password_hash() should raise E_NOTICE when password is too long for it. Actual result: -------------- Silently ignores bytes larger than 72. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67653&edit=1

« previous php.bugs (#212244) next »