Bug #78208 [Asn->Csd]: password_needs_rehash() returns false for password hashed with a different algo
| From: | pollita@php.net | Date: | Thu, 27 Jun 2019 23:28:16 +0000 |
| Subject: | Bug #78208 [Asn->Csd]: password_needs_rehash() returns false for password hashed with a different algo | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221525@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78208&edit=1
ID: 78208
Updated by: pollita@php.net
Reported by: thomas dot gerbet at enalean dot com
Summary: password_needs_rehash() returns false for password
hashed with a different algo
-Status: Assigned
+Status: Closed
Type: Bug
Package: *Encryption and hash functions
PHP Version: 7.4.0alpha1
Assigned To: pollita
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of pollita
Revision: http://git.php.net/?p=php-src.git;a=commit;h=27f1f3ed1a040a7f20bd9bb16af7bf219f4df97f
Log: Bugfix #78208 Needs rehash with an unknown algo should always return true.
Previous Comments:
------------------------------------------------------------------------
[2019-06-25 18:15:23] pollita@php.net
Confirmed. On it.
------------------------------------------------------------------------
[2019-06-25 17:41:09] thomas dot gerbet at enalean dot com
I also forgot to add that the issue is only triggered when using the PASSWORD_DEFAULT constant, with
the PASSWORD_BCRYPT constant we have the expected result.
https://3v4l.org/Z61hu
------------------------------------------------------------------------
[2019-06-25 16:21:28] requinix@php.net
This was changed as a result of the Password Hashing Registry RFC: algorithms not known to the
registry are skipped.
https://wiki.php.net/rfc/password_registry
@pollita?
------------------------------------------------------------------------
[2019-06-25 16:21:11] daverandom@php.net
Confirmed different behaviour between 7.3 and 7.4
https://3v4l.org/njXjM
------------------------------------------------------------------------
[2019-06-25 16:11:24] thomas dot gerbet at enalean dot com
Description:
------------
password hashed using crypt() with a different algorithm than the one chosen for
password_needs_rehash() are not considered as needing to be rehashed.
This behaviour is different than the one of PHP 7.1 to PHP 7.3.
Test script:
---------------
<?php
var_dump(password_needs_rehash(crypt('Example', '$1$'), PASSWORD_DEFAULT)); //
CRYPT_MD5
var_dump(password_needs_rehash(crypt('Example', '$6$rounds=5000$aa$'),
PASSWORD_DEFAULT)); // CRYPT_SHA512 with 5000 rounds
Expected result:
----------------
bool(true)
bool(true)
Actual result:
--------------
bool(false)
bool(false)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78208&edit=1