Bug #80744 [Opn->Nab]: password_verify fail to verify bcrypt hashes with cost below 4
| From: | nikic@php.net | Date: | Sat, 13 Feb 2021 14:12:51 +0000 |
| Subject: | Bug #80744 [Opn->Nab]: password_verify fail to verify bcrypt hashes with cost below 4 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-232132@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80744&edit=1
ID: 80744
Updated by: nikic@php.net
Reported by: divinity76 at gmail dot com
Summary: password_verify fail to verify bcrypt hashes with
cost below 4
-Status: Open
+Status: Not a bug
Type: Bug
Package: *Encryption and hash functions
PHP Version: 8.0.2
Block user comment: N
Private report: N
New Comment:
No, the self-test is performed with a reduced minimum cost threshold (1 instead of 16).
Previous Comments:
------------------------------------------------------------------------
[2021-02-13 14:03:41] divinity76 at gmail dot com
@allenjb
interesting, does that mean that the self-test code on line 4 here should be increased from cost 0
to cost 4? since it's not actually testing a valid bcrypt hash in it's current form?
https://github.com/php/php-src/blob/07fa13088e1349f4b5a044faeee57f2b34f6b6e4/ext/standard/crypt_blowfish.c#L814
------------------------------------------------------------------------
[2021-02-13 13:58:48] php-bugs at allenjb dot me dot uk
I would posit that this response is correct:
The original OpenBSD implementation[0], which is the closest I believe exists to a specification for
bcrypt, specifies a minimum number of 16 (2^4) rounds (BCRYPT_MINROUNDS in the OpenBSD source).
I would guess this is because lower values are likely vulnerable to the speed of brute-force
cracking even at the time the algorithm was first proposed (and we've had over 2 decades of
advances since then).
Following this "reference implementation", no library should ever generate a hash with a
cost value of less than 4, and any such hashes that exist are therefore invalid.
[0] https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/lib/libc/crypt/bcrypt.c?rev=1.1&content-type=text/x-cvsweb-markup
------------------------------------------------------------------------
[2021-02-13 13:11:08] divinity76 at gmail dot com
Description:
------------
password_verify fail to verify bcrypt hashes with cost below 4
Test script:
---------------
<?php
var_dump(password_verify("",'$2a$03$AAAAAAAAAAAAAAAAAAAAA.TCFhOtNOtk2Oeef1z4xP561tW1AQOMW'));
Expected result:
----------------
bool(true)
Actual result:
--------------
bool(false)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80744&edit=1