Req #78969 [Asn]: Expose php_password_algo_default() to userland
| From: | craig at craigfrancis dot co dot uk | Date: | Thu, 23 Jan 2020 00:48:27 +0000 |
| Subject: | Req #78969 [Asn]: Expose php_password_algo_default() to userland | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225052@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78969&edit=1
ID: 78969
User updated by: craig at craigfrancis dot co dot uk
Reported by: craig at craigfrancis dot co dot uk
Summary: Expose php_password_algo_default() to userland
Status: Assigned
Type: Feature/Change Request
Package: *General Issues
Operating System: N/A
PHP Version: 7.4.0
Assigned To: kocsismate
Block user comment: N
Private report: N
New Comment:
Thanks kocsismate, I think that works as well, and is better for backwards compatibility reasons.
But it might be worth keeping your idea for returning the default options at some point, not that I
*need* it, but someone might (says he knowing that we should only add things to PHP that people will
actually use).
Previous Comments:
------------------------------------------------------------------------
[2020-01-22 21:59:13] kocsismate@php.net
The ship is sailing in another direction... :) So it might be possible to fix the issue in a next
minor version of PHP 7.4. See the discussion in the PR for context.
------------------------------------------------------------------------
[2020-01-22 00:23:43] craig at craigfrancis dot co dot uk
Thanks kocsismate, I like your idea of matching
password_get_info() with the ability to
see the default options as well, thatâs a really nice touch.
------------------------------------------------------------------------
[2020-01-21 23:28:29] kocsismate@php.net
Hi Craig,
I've just opened a PR in order to add the missing functionality: https://github.com/php/php-src/pull/5104
Don't hesitate to give feedback about the (preliminary) implementation.
------------------------------------------------------------------------
[2019-12-16 16:20:22] craig at craigfrancis dot co dot uk
> "This decreases the overall security of the hash [...] don't hash hashes"
Not so for bcrypt... which is an old-ish hashing algorithm, with 2 fairly well known issues
(fortunately they are also minor, so most programmers shouldn't care).
The quick hash before solves those issues (this is why Scott Arciszewski and Dropbox do it); but you
are right in general, this would be bad for future algorithms (such as Argon2), and is why I only
want to do this for bcrypt, while being ready for when PASSWORD_DEFAULT moves away from bcrypt.
------------------------------------------------------------------------
[2019-12-16 15:05:34] requinix@php.net
Note that new hashing algorithms are mandated to only be added during major (x.0.0) or minor (x.y.0)
releases. So for the lifetime of PHP 7.4, bcrypt is the default.
> I do a quick hash of the password before passing it into password_hash()
This decreases the overall security of the hash. Even if it's "boring cryptography",
please don't do this. It's a matter of principle: don't hash hashes.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78969
--
Edit this bug report at https://bugs.php.net/bug.php?id=78969&edit=1