Req #78969 [Asn]: Expose php_password_algo_default() to userland

From: Date: Thu, 23 Jan 2020 00:48:27 +0000
Subject: Req #78969 [Asn]: Expose php_password_algo_default() to userland
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225052@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78969&edit=1 ID: 78969 User updated by: craig at craigfrancis dot co dot uk Reported by: craig at craigfrancis dot co dot uk Summary: Expose php_password_algo_default() to userland Status: Assigned Type: Feature/Change Request Package: *General Issues Operating System: N/A PHP Version: 7.4.0 Assigned To: kocsismate Block user comment: N Private report: N New Comment: Thanks kocsismate, I think that works as well, and is better for backwards compatibility reasons. But it might be worth keeping your idea for returning the default options at some point, not that I *need* it, but someone might (says he knowing that we should only add things to PHP that people will actually use). Previous Comments: ------------------------------------------------------------------------ [2020-01-22 21:59:13] kocsismate@php.net The ship is sailing in another direction... :) So it might be possible to fix the issue in a next minor version of PHP 7.4. See the discussion in the PR for context. ------------------------------------------------------------------------ [2020-01-22 00:23:43] craig at craigfrancis dot co dot uk Thanks kocsismate, I like your idea of matching password_get_info() with the ability to see the default options as well, that’s a really nice touch. ------------------------------------------------------------------------ [2020-01-21 23:28:29] kocsismate@php.net Hi Craig, I've just opened a PR in order to add the missing functionality: https://github.com/php/php-src/pull/5104 Don't hesitate to give feedback about the (preliminary) implementation. ------------------------------------------------------------------------ [2019-12-16 16:20:22] craig at craigfrancis dot co dot uk > "This decreases the overall security of the hash [...] don't hash hashes" Not so for bcrypt... which is an old-ish hashing algorithm, with 2 fairly well known issues (fortunately they are also minor, so most programmers shouldn't care). The quick hash before solves those issues (this is why Scott Arciszewski and Dropbox do it); but you are right in general, this would be bad for future algorithms (such as Argon2), and is why I only want to do this for bcrypt, while being ready for when PASSWORD_DEFAULT moves away from bcrypt. ------------------------------------------------------------------------ [2019-12-16 15:05:34] requinix@php.net Note that new hashing algorithms are mandated to only be added during major (x.0.0) or minor (x.y.0) releases. So for the lifetime of PHP 7.4, bcrypt is the default. > I do a quick hash of the password before passing it into password_hash() This decreases the overall security of the hash. Even if it's "boring cryptography", please don't do this. It's a matter of principle: don't hash hashes. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78969 -- Edit this bug report at https://bugs.php.net/bug.php?id=78969&edit=1

« previous php.bugs (#225052) next »