Bug #78969 [NEW]: No way to tell if bcrypt will be used in password_hash by default
| From: | craig at craigfrancis dot co dot uk | Date: | Mon, 16 Dec 2019 12:14:33 +0000 |
| Subject: | Bug #78969 [NEW]: No way to tell if bcrypt will be used in password_hash by default | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-224339@lists.php.net to get a copy of this message | ||
From: craig at craigfrancis dot co dot uk
Operating system: N/A
PHP version: 7.4.0
Package: hash related
Bug Type: Bug
Bug description:No way to tell if bcrypt will be used in password_hash by default
Description:
------------
PHP 7.3 allows you to determine if the default password hashing
algorithm will be bcrypt.
PHP 7.4 defines PASSWORD_DEFAULT as NULL, so you can't tell what
password_hash() will use.
For most systems this is fine, but bcrypt does have a couple of little
issues (the limit of 72 characters for many implementations, and how it
handles the NULL character).
So following the advice from ParagonIE and Dropbox, I do a quick hash of
the password before passing it into password_hash(). But this work
around won't be necessary for Argon2, or future password hashing
methods.
https://stackoverflow.com/questions/59273258/identifying-what-password-default-will-be-in-php-7-4
https://paragonie.com/blog/2016/02/how-safely-store-password-in-2016#why-scrypt
https://blogs.dropbox.com/tech/2016/09/how-dropbox-securely-stores-your-passwords/
Test script:
---------------
$password = normalizer_normalize($password, Normalizer::FORM_KD);
if (PASSWORD_DEFAULT === PASSWORD_BCRYPT) {
$password = base64_encode(hash('sha384', $password, true));
}
$hash = password_hash($password, PASSWORD_DEFAULT);
--
Edit bug report at https://bugs.php.net/bug.php?id=78969&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=78969&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78969&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78969&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78969&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78969&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78969&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78969&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78969&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78969&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78969&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78969&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=78969&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78969&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78969&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78969&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78969&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78969&r=mysqlcfg