Bug #78208 [Asn]: password_needs_rehash() returns false for password hashed with a different algo
| From: | pollita@php.net | Date: | Tue, 25 Jun 2019 18:15:24 +0000 |
| Subject: | Bug #78208 [Asn]: password_needs_rehash() returns false for password hashed with a different algo | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221493@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78208&edit=1
ID: 78208
Updated by: pollita@php.net
Reported by: thomas dot gerbet at enalean dot com
Summary: password_needs_rehash() returns false for password
hashed with a different algo
Status: Assigned
Type: Bug
Package: *Encryption and hash functions
PHP Version: 7.4.0alpha1
Assigned To: pollita
Block user comment: N
Private report: N
New Comment:
Confirmed. On it.
Previous Comments:
------------------------------------------------------------------------
[2019-06-25 17:41:09] thomas dot gerbet at enalean dot com
I also forgot to add that the issue is only triggered when using the PASSWORD_DEFAULT constant, with
the PASSWORD_BCRYPT constant we have the expected result.
https://3v4l.org/Z61hu
------------------------------------------------------------------------
[2019-06-25 16:21:28] requinix@php.net
This was changed as a result of the Password Hashing Registry RFC: algorithms not known to the
registry are skipped.
https://wiki.php.net/rfc/password_registry
@pollita?
------------------------------------------------------------------------
[2019-06-25 16:21:11] daverandom@php.net
Confirmed different behaviour between 7.3 and 7.4
https://3v4l.org/njXjM
------------------------------------------------------------------------
[2019-06-25 16:11:24] thomas dot gerbet at enalean dot com
Description:
------------
password hashed using crypt() with a different algorithm than the one chosen for
password_needs_rehash() are not considered as needing to be rehashed.
This behaviour is different than the one of PHP 7.1 to PHP 7.3.
Test script:
---------------
<?php
var_dump(password_needs_rehash(crypt('Example', '$1$'), PASSWORD_DEFAULT)); //
CRYPT_MD5
var_dump(password_needs_rehash(crypt('Example', '$6$rounds=5000$aa$'),
PASSWORD_DEFAULT)); // CRYPT_SHA512 with 5000 rounds
Expected result:
----------------
bool(true)
bool(true)
Actual result:
--------------
bool(false)
bool(false)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78208&edit=1