Req #78969 [Opn]: Expose php_password_algo_default() to userland
| From: | craig at craigfrancis dot co dot uk | Date: | Mon, 16 Dec 2019 16:20:22 +0000 |
| Subject: | Req #78969 [Opn]: Expose php_password_algo_default() to userland | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224346@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78969&edit=1
ID: 78969
User updated by: craig at craigfrancis dot co dot uk
Reported by: craig at craigfrancis dot co dot uk
Summary: Expose php_password_algo_default() to userland
Status: Open
Type: Feature/Change Request
Package: *General Issues
Operating System: N/A
PHP Version: 7.4.0
Block user comment: N
Private report: N
New Comment:
> "This decreases the overall security of the hash [...] don't hash hashes"
Not so for bcrypt... which is an old-ish hashing algorithm, with 2 fairly well known issues
(fortunately they are also minor, so most programmers shouldn't care).
The quick hash before solves those issues (this is why Scott Arciszewski and Dropbox do it); but you
are right in general, this would be bad for future algorithms (such as Argon2), and is why I only
want to do this for bcrypt, while being ready for when PASSWORD_DEFAULT moves away from bcrypt.
Previous Comments:
------------------------------------------------------------------------
[2019-12-16 15:05:34] requinix@php.net
Note that new hashing algorithms are mandated to only be added during major (x.0.0) or minor (x.y.0)
releases. So for the lifetime of PHP 7.4, bcrypt is the default.
> I do a quick hash of the password before passing it into password_hash()
This decreases the overall security of the hash. Even if it's "boring cryptography",
please don't do this. It's a matter of principle: don't hash hashes.
------------------------------------------------------------------------
[2019-12-16 12:14:33] craig at craigfrancis dot co dot uk
Description:
------------
PHP 7.3 allows you to determine if the default password hashing algorithm will be bcrypt.
PHP 7.4 defines PASSWORD_DEFAULT as NULL, so you can't tell what password_hash() will use.
For most systems this is fine, but bcrypt does have a couple of little issues (the limit of 72
characters for many implementations, and how it handles the NULL character).
So following the advice from ParagonIE and Dropbox, I do a quick hash of the password before passing
it into password_hash(). But this work around won't be necessary for Argon2, or future password
hashing methods.
https://stackoverflow.com/questions/59273258/identifying-what-password-default-will-be-in-php-7-4
https://paragonie.com/blog/2016/02/how-safely-store-password-in-2016#why-scrypt
https://blogs.dropbox.com/tech/2016/09/how-dropbox-securely-stores-your-passwords/
Test script:
---------------
$password = normalizer_normalize($password, Normalizer::FORM_KD);
if (PASSWORD_DEFAULT === PASSWORD_BCRYPT) {
$password = base64_encode(hash('sha384', $password, true));
}
$hash = password_hash($password, PASSWORD_DEFAULT);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78969&edit=1