Bug #78969 [NEW]: No way to tell if bcrypt will be used in password_hash by default

From: Date: Mon, 16 Dec 2019 12:14:33 +0000
Subject: Bug #78969 [NEW]: No way to tell if bcrypt will be used in password_hash by default
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224339@lists.php.net to get a copy of this message
From: craig at craigfrancis dot co dot uk Operating system: N/A PHP version: 7.4.0 Package: hash related Bug Type: Bug Bug description:No way to tell if bcrypt will be used in password_hash by default Description: ------------ PHP 7.3 allows you to determine if the default password hashing algorithm will be bcrypt. PHP 7.4 defines PASSWORD_DEFAULT as NULL, so you can't tell what password_hash() will use. For most systems this is fine, but bcrypt does have a couple of little issues (the limit of 72 characters for many implementations, and how it handles the NULL character). So following the advice from ParagonIE and Dropbox, I do a quick hash of the password before passing it into password_hash(). But this work around won't be necessary for Argon2, or future password hashing methods. https://stackoverflow.com/questions/59273258/identifying-what-password-default-will-be-in-php-7-4 https://paragonie.com/blog/2016/02/how-safely-store-password-in-2016#why-scrypt https://blogs.dropbox.com/tech/2016/09/how-dropbox-securely-stores-your-passwords/ Test script: --------------- $password = normalizer_normalize($password, Normalizer::FORM_KD); if (PASSWORD_DEFAULT === PASSWORD_BCRYPT) { $password = base64_encode(hash('sha384', $password, true)); } $hash = password_hash($password, PASSWORD_DEFAULT); -- Edit bug report at https://bugs.php.net/bug.php?id=78969&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=78969&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=78969&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=78969&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=78969&r=needscript Try newer version: https://bugs.php.net/fix.php?id=78969&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=78969&r=support Expected behavior: https://bugs.php.net/fix.php?id=78969&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=78969&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=78969&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=78969&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=78969&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=78969&r=dst IIS Stability: https://bugs.php.net/fix.php?id=78969&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=78969&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=78969&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=78969&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=78969&r=mysqlcfg

« previous php.bugs (#224339) next »