Req #77134 [Opn->Nab]: password_needs_rehash will flag a superior password
| From: | requinix@php.net | Date: | Sat, 10 Nov 2018 05:57:56 +0000 |
| Subject: | Req #77134 [Opn->Nab]: password_needs_rehash will flag a superior password | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217888@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77134&edit=1
ID: 77134
Updated by: requinix@php.net
Reported by: dsumner at sumone dot ca
Summary: password_needs_rehash will flag a superior password
-Status: Open
+Status: Not a bug
Type: Feature/Change Request
Package: hash related
Operating System: all
PHP Version: 7.0.32
Block user comment: N
Private report: N
New Comment:
"This function checks to see if the supplied hash implements the algorithm and options
provided."
It does not try to decide "superiority".
If you know the hash should be generated with particular options then pass those to
password_needs_rehash.
Previous Comments:
------------------------------------------------------------------------
[2018-11-10 05:48:37] dsumner at sumone dot ca
Description:
------------
On my website I am hashing all passwords with a cost of 7 (There is really no great security need).
When a user logs on their password is checked with password_needs_rehash and it work well except
that I want certain users to have a password with a higher cost than most users. I can generate
their hashes quite easily, but when password_needs_rehash sees these "superior" passwords
it returns TRUE and the logon logic then automatically downgrades their passwords.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77134&edit=1