Bug #81491 [Com]: Incorrectly using libsodium for argon2 hashing
| From: | josephlindquist92 at yahoo dot com | Date: | Fri, 01 Oct 2021 07:12:42 +0000 |
| Subject: | Bug #81491 [Com]: Incorrectly using libsodium for argon2 hashing | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-236949@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81491&edit=1
ID: 81491
Comment by: josephlindquist92 at yahoo dot com
Reported by: dpock at liquidweb dot com
Summary: Incorrectly using libsodium for argon2 hashing
Status: Open
Type: Bug
Package: *Compile Issues
PHP Version: 8.1Git-2021-09-30 (Git)
Block user comment: N
Private report: N
New Comment:
There are other implementations of Argon2 in the Node.js ecosystem, but you are probably better off
using nodes with sodium to handle salt production for you. Argon2 is available to developers as help
from for your written work https://essayservices.org/ .NET
binding to libsodium. Starting with version 10.8 it provides a secure password hashing API for most
languages using the scrypt algorithm, and in next version (10.9) it offers Argon2 as the last
selected algorithm in the password hashing competition.
The documentation recommends that users prepack passwords with Blake2B, use scrypt, and provide a
secure alternative to argon2 by deriving the keyword from crypto / pwhash / scrypt.salsa.208.sha256
_ str _ password, and then hashing the password with a 65-byte hash of unsalted SHA-256. In order to
reduce the exhaustion of the password, a client is hashed in advance.
The next step is to add a secret key to the hash so that anyone who knows the secret key can use it
to validate the password. This is not as secure as using a separate system password hash since there
are SQL injection vulnerabilities in web applications and other types, such as local file mounts,
that an attacker can use to read the secret keys from a file. The main problem is that it allows
access to the plaintext password, so an attacker with direct access to memory is more dangerous than
someone with access to a hash.
The real application for us is to keep the hash value in the database and use it at the next login
to verify the user password. To do this, recalculate the bcrypt-password and store the new hash in
the database, this will be enabled using the old password flag.
Previous Comments:
------------------------------------------------------------------------
[2021-09-30 18:00:27] dpock at liquidweb dot com
After further investigation I found the root cause to be that
HAVE_ARGON2LIB was not
being defined when the argon2 config flag is set.
I've updated the patch in the PR to reflect this here: https://github.com/php/php-src/pull/7538
------------------------------------------------------------------------
[2021-09-30 17:32:52] dpock at liquidweb dot com
Description:
------------
It appears that PHP-8.1 branch is no longer compiling libargon2 support correctly. The effect of
this vary depending on if libsodium is present too.
When libsodium is present, the issue is observed are:
* Cannot use threads option when hashing with argon2,
* PASSWORD_ARGON2_PROVIDER reports as 'sodium'
When libsodium is not present, the issue observed is:
* Error stating argon2 is not supported
---
Note: Left OS blank as this affects my Mac, as well as linux based GitHub runners.
---
I have 'confirmed' this bug by compiling PHP 8.0 and PHP 8.1 using the same settings. When
using PHP 8.0 w/o sodium I can still use argon2, and similarly the threads option works when
hashing.
I've also made a "PR" that confirms PHP 8.1 works when I revert a commit to load
argon2 via pkg-config rather than config flags. This PR is here: https://github.com/php/php-src/pull/7538
Test script:
---------------
This bug was initially found by Dries Vints via failing CI tests here: https://github.com/laravel/framework/runs/3599702797#step:8:126
He was observing the issue with "threads" value greater than 1 causing an error. This is
behavior you'd only expect if PHP were compiled with ONLY libsodium. However the GitHub
runner's in use should be compiling with BOTH libsodium and libargon2. We can be confident they
are compiling in this manner as PHP 8.0 runners (from the same source) are working correctly.
Expected result:
----------------
PHP should know it has access to both libsodium and libargon2 when
compiled in this manner.
As such, when PHP compiles with both libs, we should see:
* PASSWORD_ARGON2_PROVIDER should be 'standard', and
* password_hash should accept threads > 1 when using argon2.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81491&edit=1