Bug #78208 [Asn]: password_needs_rehash() returns false for password hashed with a different algo

From: Date: Tue, 25 Jun 2019 18:15:24 +0000
Subject: Bug #78208 [Asn]: password_needs_rehash() returns false for password hashed with a different algo
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221493@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78208&edit=1 ID: 78208 Updated by: pollita@php.net Reported by: thomas dot gerbet at enalean dot com Summary: password_needs_rehash() returns false for password hashed with a different algo Status: Assigned Type: Bug Package: *Encryption and hash functions PHP Version: 7.4.0alpha1 Assigned To: pollita Block user comment: N Private report: N New Comment: Confirmed. On it. Previous Comments: ------------------------------------------------------------------------ [2019-06-25 17:41:09] thomas dot gerbet at enalean dot com I also forgot to add that the issue is only triggered when using the PASSWORD_DEFAULT constant, with the PASSWORD_BCRYPT constant we have the expected result. https://3v4l.org/Z61hu ------------------------------------------------------------------------ [2019-06-25 16:21:28] requinix@php.net This was changed as a result of the Password Hashing Registry RFC: algorithms not known to the registry are skipped. https://wiki.php.net/rfc/password_registry @pollita? ------------------------------------------------------------------------ [2019-06-25 16:21:11] daverandom@php.net Confirmed different behaviour between 7.3 and 7.4 https://3v4l.org/njXjM ------------------------------------------------------------------------ [2019-06-25 16:11:24] thomas dot gerbet at enalean dot com Description: ------------ password hashed using crypt() with a different algorithm than the one chosen for password_needs_rehash() are not considered as needing to be rehashed. This behaviour is different than the one of PHP 7.1 to PHP 7.3. Test script: --------------- <?php var_dump(password_needs_rehash(crypt('Example', '$1$'), PASSWORD_DEFAULT)); // CRYPT_MD5 var_dump(password_needs_rehash(crypt('Example', '$6$rounds=5000$aa$'), PASSWORD_DEFAULT)); // CRYPT_SHA512 with 5000 rounds Expected result: ---------------- bool(true) bool(true) Actual result: -------------- bool(false) bool(false) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78208&edit=1

« previous php.bugs (#221493) next »