Bug->Req #67653 [Opn]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently

From: Date: Wed, 23 Dec 2020 17:05:56 +0000
Subject: Bug->Req #67653 [Opn]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231242@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67653&edit=1 ID: 67653 Updated by: cmb@php.net Reported by: yohgaki at ohgaki dot net Summary: PASSWORD_BCRYPT truncates password longer than 72 bytes silently Status: Open -Type: Bug +Type: Feature/Change Request -Package: hash related +Package: *Encryption and hash functions Operating System: Irrelevant PHP Version: 5.5 Block user comment: N Private report: N New Comment: Known issue; changing to feature request. Previous Comments: ------------------------------------------------------------------------ [2014-07-19 01:58:40] yohgaki at ohgaki dot net Description: ------------ PASSWORD_BCRYPT truncates password longer than 72 bytes silently Test script: --------------- [yohgaki@dev tmp]$ php -r 'var_dump(password_verify("123456789012345678901234567890123456789012345678901234567890123456789012", password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890", PASSWORD_DEFAULT)));' bool(true) [yohgaki@dev tmp]$ php -r 'var_dump(password_verify("12345678901234567890123456789012345678901234567890123456789012345678901", password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890", PASSWORD_DEFAULT)));' bool(false) Expected result: ---------------- password_hash() should raise E_NOTICE when password is too long for it. Actual result: -------------- Silently ignores bytes larger than 72. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67653&edit=1

« previous php.bugs (#231242) next »