Bug->Req #67653 [Opn]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently
| From: | cmb@php.net | Date: | Wed, 23 Dec 2020 17:05:56 +0000 |
| Subject: | Bug->Req #67653 [Opn]: PASSWORD_BCRYPT truncates password longer than 72 bytes silently | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-231242@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67653&edit=1
ID: 67653
Updated by: cmb@php.net
Reported by: yohgaki at ohgaki dot net
Summary: PASSWORD_BCRYPT truncates password longer than 72
bytes silently
Status: Open
-Type: Bug
+Type: Feature/Change Request
-Package: hash related
+Package: *Encryption and hash functions
Operating System: Irrelevant
PHP Version: 5.5
Block user comment: N
Private report: N
New Comment:
Known issue; changing to feature request.
Previous Comments:
------------------------------------------------------------------------
[2014-07-19 01:58:40] yohgaki at ohgaki dot net
Description:
------------
PASSWORD_BCRYPT truncates password longer than 72 bytes silently
Test script:
---------------
[yohgaki@dev tmp]$ php -r
'var_dump(password_verify("123456789012345678901234567890123456789012345678901234567890123456789012",
password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890",
PASSWORD_DEFAULT)));'
bool(true)
[yohgaki@dev tmp]$ php -r
'var_dump(password_verify("12345678901234567890123456789012345678901234567890123456789012345678901",
password_hash("12345678901234567890123456789012345678901234567890123456789012345678901234567890",
PASSWORD_DEFAULT)));'
bool(false)
Expected result:
----------------
password_hash() should raise E_NOTICE when password is too long for it.
Actual result:
--------------
Silently ignores bytes larger than 72.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67653&edit=1