Bug #78208 [Opn->Ver]: password_needs_rehash() returns false for password hashed with a different algo
| From: | daverandom@php.net | Date: | Tue, 25 Jun 2019 16:21:11 +0000 |
| Subject: | Bug #78208 [Opn->Ver]: password_needs_rehash() returns false for password hashed with a different algo | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221484@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78208&edit=1
ID: 78208
Updated by: daverandom@php.net
Reported by: thomas dot gerbet at enalean dot com
Summary: password_needs_rehash() returns false for password
hashed with a different algo
-Status: Open
+Status: Verified
Type: Bug
Package: *Encryption and hash functions
PHP Version: 7.4.0alpha1
Block user comment: N
Private report: N
New Comment:
Confirmed different behaviour between 7.3 and 7.4
https://3v4l.org/njXjM
Previous Comments:
------------------------------------------------------------------------
[2019-06-25 16:11:24] thomas dot gerbet at enalean dot com
Description:
------------
password hashed using crypt() with a different algorithm than the one chosen for
password_needs_rehash() are not considered as needing to be rehashed.
This behaviour is different than the one of PHP 7.1 to PHP 7.3.
Test script:
---------------
<?php
var_dump(password_needs_rehash(crypt('Example', '$1$'), PASSWORD_DEFAULT)); //
CRYPT_MD5
var_dump(password_needs_rehash(crypt('Example', '$6$rounds=5000$aa$'),
PASSWORD_DEFAULT)); // CRYPT_SHA512 with 5000 rounds
Expected result:
----------------
bool(true)
bool(true)
Actual result:
--------------
bool(false)
bool(false)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78208&edit=1