Req #76013 [Com]: Add simple hashes support in password_verify
| From: | anrdaemon at freemail dot ru | Date: | Tue, 27 Feb 2018 12:49:59 +0000 |
| Subject: | Req #76013 [Com]: Add simple hashes support in password_verify | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214126@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76013&edit=1
ID: 76013
Comment by: anrdaemon at freemail dot ru
Reported by: anrdaemon at freemail dot ru
Summary: Add simple hashes support in password_verify
Status: Feedback
Type: Feature/Change Request
Package: hash related
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
md5 and sha1 hashes have well known lengths. I presume the length of the passed buffer is readily
available, so you don't have to manually count bytes each time you want to know it.
If no hashing signatures were found in a string, and the length is matching one of the two known
values, try to use appropriate plain hashing function.
This is not related to salted plain hashes, if anybody was using such a trick, it's up to them
to sort the mess they have created.
This is only limited to hashing functions natively provided by PHP (both md5 and sha1 availability
predates PHP5). If anybody was using extensions, or database functions, this is out of scope of the
proposal.
This proposal does not include CRC32(the only other string hashing option available). A joke is too
severe to seriously consider it as password hashing algo.
Previous Comments:
------------------------------------------------------------------------
[2018-02-27 11:12:17] cmb@php.net
How is this supposed to work? The hashes supported by the
password_*() functions clearly identify the hash algorithm
(including any options), and also contain the salt that has been
used to produce the hash. While it would be possible to guess the
algorithm for "plain hashes" (I doubt that this would be a good
idea, though), the salt would be unknown.
------------------------------------------------------------------------
[2018-02-26 17:45:40] anrdaemon at freemail dot ru
Description:
------------
If only password_verify could support regular md5/sha1 hashes, it would make hell of a jumpstart for
old applications migrating to new hashing schemes.
Test script:
---------------
<?php
$pass = 'MyCoolPass';
$md5 = md5($pass);
$sha1 = sha1($pass);
$crypt = crypt($pass);
$crypts = crypt($pass, (string)rand());
$hash = password_hash($pass, PASSWORD_DEFAULT);
var_dump(
password_get_info($md5), password_get_info($sha1),
password_get_info($crypt), password_get_info($crypts),
password_get_info($hash),
password_verify($pass, $md5), password_needs_rehash($md5, PASSWORD_DEFAULT),
password_verify($pass, $sha1), password_needs_rehash($sha1, PASSWORD_DEFAULT),
password_verify($pass, $crypt), password_needs_rehash($crypt, PASSWORD_DEFAULT),
password_verify($pass, $crypts), password_needs_rehash($crypts, PASSWORD_DEFAULT),
password_verify($pass, $hash), password_needs_rehash($hash, PASSWORD_DEFAULT)
);
Expected result:
----------------
bool(true)
bool(true)
bool(true)
bool(true)
bool(true)
bool(true)
bool(true)
bool(true)
bool(true)
bool(false)
Actual result:
--------------
bool(false)
bool(true)
bool(false)
bool(true)
bool(true)
bool(true)
bool(true)
bool(true)
bool(true)
bool(false)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76013&edit=1