Req #75388 [Com]: Argon2: Add secret/key

From: Date: Thu, 28 Mar 2019 19:50:45 +0000
Subject: Req #75388 [Com]: Argon2: Add secret/key
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220239@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75388&edit=1 ID: 75388 Comment by: davidapgilman at gmail dot com Reported by: phpdoc at mail dot my1 dot info Summary: Argon2: Add secret/key Status: Assigned Type: Feature/Change Request Package: *Encryption and hash functions Operating System: Win8.1 x64 PHP Version: Next Minor Version Assigned To: jedisct1 Block user comment: N Private report: N New Comment: I concur with the OP - the best way to use a pepper with Argon2 is to use the built in "secret" parameter. There are workarounds as suggested, but the most elegant, audited, and cryptographically secure method is to use the built-in secret parameter as designed. I understand if there are higher priority PRs, but it's negligent and ignorant to choose to leave off a built-in security feature of the PHC winner. You're encouraging developers to roll their own encryption at worst, and forcing them to choose between a number of non-intuitive workarounds at best. I'd like to re-request this feature. Previous Comments: ------------------------------------------------------------------------ [2018-06-16 16:22:53] phpdoc at mail dot my1 dot info @jedisct1 last time I checked, the ability of using arbitrary salts wasnt available for PASSWORD_ARGON2I and only for PASSWORD_BCRYPT and even that is deprecated. and as stange already says it is exposed by other languages and on top of it, it is a part of argon. why should one go with playing on the salt using a pseudorandom function with both a self made salt and a secret if argon can accept secrets by itself and just use that? also it's probably more secure than a self-built workaround anyway. ------------------------------------------------------------------------ [2018-03-29 15:08:56] jedisct1@php.net If you really need this, don't store the salt itself. Generate and store a random s, and use prf(k, s) as the salt. This is equivalent to adding a secret key to the initial Argon2 state. A major drawback is the fact that keys cannot be rotated. A way better approach is to encrypt the hashes. You may also want to add an authentication tag that includes the salt and parameters, to prevent resources starvation if the parameters get modified while still allowing parameter updates. Authenticated encryption is beyond the scope of a password hashing function. Combining both in a simple way is an API's responsibility. libsodium 2.x will use the libhydrogen API, but the password hashing API might be backported to the 1.x branch: https://github.com/jedisct1/libhydrogen/wiki/Password-hashing ------------------------------------------------------------------------ [2018-03-29 14:07:22] stange at digitalriver dot com The secret is an important feature with argon2. Other languages expose it. ------------------------------------------------------------------------ [2018-03-29 14:07:19] stange at digitalriver dot com The secret is an important feature with argon2. Other languages expose it. ------------------------------------------------------------------------ [2017-10-17 16:20:53] cmb@php.net Feedback has been provided, so opening again. Assigning to Frank, since he implemented the argon2 password hashing for PHP, and apparently doesn't like non-replaceable keys[1]. Besides, using the secret key doesn't appear to work with argon2*_hash_encoded(). [1] <https://github.com/P-H-C/phc-winner-argon2/issues/222> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75388 -- Edit this bug report at https://bugs.php.net/bug.php?id=75388&edit=1

« previous php.bugs (#220239) next »