Req #78969 [Opn]: Expose php_password_algo_default() to userland

From: Date: Mon, 16 Dec 2019 16:20:22 +0000
Subject: Req #78969 [Opn]: Expose php_password_algo_default() to userland
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224346@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78969&edit=1 ID: 78969 User updated by: craig at craigfrancis dot co dot uk Reported by: craig at craigfrancis dot co dot uk Summary: Expose php_password_algo_default() to userland Status: Open Type: Feature/Change Request Package: *General Issues Operating System: N/A PHP Version: 7.4.0 Block user comment: N Private report: N New Comment: > "This decreases the overall security of the hash [...] don't hash hashes" Not so for bcrypt... which is an old-ish hashing algorithm, with 2 fairly well known issues (fortunately they are also minor, so most programmers shouldn't care). The quick hash before solves those issues (this is why Scott Arciszewski and Dropbox do it); but you are right in general, this would be bad for future algorithms (such as Argon2), and is why I only want to do this for bcrypt, while being ready for when PASSWORD_DEFAULT moves away from bcrypt. Previous Comments: ------------------------------------------------------------------------ [2019-12-16 15:05:34] requinix@php.net Note that new hashing algorithms are mandated to only be added during major (x.0.0) or minor (x.y.0) releases. So for the lifetime of PHP 7.4, bcrypt is the default. > I do a quick hash of the password before passing it into password_hash() This decreases the overall security of the hash. Even if it's "boring cryptography", please don't do this. It's a matter of principle: don't hash hashes. ------------------------------------------------------------------------ [2019-12-16 12:14:33] craig at craigfrancis dot co dot uk Description: ------------ PHP 7.3 allows you to determine if the default password hashing algorithm will be bcrypt. PHP 7.4 defines PASSWORD_DEFAULT as NULL, so you can't tell what password_hash() will use. For most systems this is fine, but bcrypt does have a couple of little issues (the limit of 72 characters for many implementations, and how it handles the NULL character). So following the advice from ParagonIE and Dropbox, I do a quick hash of the password before passing it into password_hash(). But this work around won't be necessary for Argon2, or future password hashing methods. https://stackoverflow.com/questions/59273258/identifying-what-password-default-will-be-in-php-7-4 https://paragonie.com/blog/2016/02/how-safely-store-password-in-2016#why-scrypt https://blogs.dropbox.com/tech/2016/09/how-dropbox-securely-stores-your-passwords/ Test script: --------------- $password = normalizer_normalize($password, Normalizer::FORM_KD); if (PASSWORD_DEFAULT === PASSWORD_BCRYPT) { $password = base64_encode(hash('sha384', $password, true)); } $hash = password_hash($password, PASSWORD_DEFAULT); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78969&edit=1

« previous php.bugs (#224346) next »