Req #78969 [Asn->Csd]: Expose php_password_algo_default() to userland
| From: | kocsismate@php.net | Date: | Mon, 27 Jan 2020 12:58:38 +0000 |
| Subject: | Req #78969 [Asn->Csd]: Expose php_password_algo_default() to userland | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225142@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78969&edit=1
ID: 78969
Updated by: kocsismate@php.net
Reported by: craig at craigfrancis dot co dot uk
Summary: Expose php_password_algo_default() to userland
-Status: Assigned
+Status: Closed
Type: Feature/Change Request
Package: *General Issues
Operating System: N/A
PHP Version: 7.4.0
Assigned To: kocsismate
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of kocsismate@woohoolabs.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ea1b8788773fe9d5fd517704da332f0725714b8b
Log: Fix #78969 Make PASSWORD_DEFAULT match PASSWORD_BCRYPT instead of being null
Previous Comments:
------------------------------------------------------------------------
[2020-01-23 00:48:27] craig at craigfrancis dot co dot uk
Thanks kocsismate, I think that works as well, and is better for backwards compatibility reasons.
But it might be worth keeping your idea for returning the default options at some point, not that I
*need* it, but someone might (says he knowing that we should only add things to PHP that people will
actually use).
------------------------------------------------------------------------
[2020-01-22 21:59:13] kocsismate@php.net
The ship is sailing in another direction... :) So it might be possible to fix the issue in a next
minor version of PHP 7.4. See the discussion in the PR for context.
------------------------------------------------------------------------
[2020-01-22 00:23:43] craig at craigfrancis dot co dot uk
Thanks kocsismate, I like your idea of matching
password_get_info() with the ability to
see the default options as well, thatâs a really nice touch.
------------------------------------------------------------------------
[2020-01-21 23:28:29] kocsismate@php.net
Hi Craig,
I've just opened a PR in order to add the missing functionality: https://github.com/php/php-src/pull/5104
Don't hesitate to give feedback about the (preliminary) implementation.
------------------------------------------------------------------------
[2019-12-16 16:20:22] craig at craigfrancis dot co dot uk
> "This decreases the overall security of the hash [...] don't hash hashes"
Not so for bcrypt... which is an old-ish hashing algorithm, with 2 fairly well known issues
(fortunately they are also minor, so most programmers shouldn't care).
The quick hash before solves those issues (this is why Scott Arciszewski and Dropbox do it); but you
are right in general, this would be bad for future algorithms (such as Argon2), and is why I only
want to do this for bcrypt, while being ready for when PASSWORD_DEFAULT moves away from bcrypt.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78969
--
Edit this bug report at https://bugs.php.net/bug.php?id=78969&edit=1