Doc #64816 [Opn->Ana]: CRYPT_BLOWFISH is not better than PBKDF2

From: Date: Fri, 28 Jun 2013 06:57:58 +0000
Subject: Doc #64816 [Opn->Ana]: CRYPT_BLOWFISH is not better than PBKDF2
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-10022@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64816&edit=1 ID: 64816 Updated by: yohgaki@php.net Reported by: nenolod at dereferenced dot org Summary: CRYPT_BLOWFISH is not better than PBKDF2 -Status: Open +Status: Analyzed Type: Documentation Problem Package: Documentation problem Operating System: N/A PHP Version: 5.5.0RC1 Block user comment: N Private report: N New Comment: From the manual ================== Caution The PBKDF2 method can be used for hashing passwords for storage (it is NIST approved for that use). However, it should be noted that CRYPT_BLOWFISH is better suited for password storage and should be used instead via crypt(). ================== This is too much. There are several problems. 1. crypt() is not encouraged, password_hash() is. (PHP 5.5>=) 2. PHP 5.5 users are encouraged to use password_hash() since it allows to upgrade hashing algorithm by upgrading PHP. (i.e. automatically updates algorithm) 3. Both password_hash() and hash_pbkdf2() are good enough if users used them with correct parameters. Note that correct usage is important for robust security. RFC 2898 suggest 1000+ rounds and NIST suggests several thousands rounds with SHA2 hashing. However, these number may consider too few with current technology. http://security.stackexchange.com/questions/3959/recommended-of-iterations-when- using-pkbdf2-sha256 It recommends tens of thousands rounds with SHA2 hash. Anyway, both password_hash(), which uses crypt+blowfish internally, and hash_pbkdf2() good enough if users set at least 10000 rounds with SHA2 hash. (I would recommend 20000+, though) I know there are number of weaknesses of blowfish have been reported, but it wouldn't be a problem with password length longer than 8 chars (I would recommend at least 10. 12+ is better) Current password_hash() uses a little few rounds(2^10 = 1024). Since hash computation execution efficiency is differ from SHA2, blowfish requires less rounds and 1024 is acceptable, IMO. (I would suggest 2^12 or more, though) Anyway, many users don't have clue about password hashing and current documentation cannot consider correct. Doc should be updated. Previous Comments: ------------------------------------------------------------------------ [2013-05-11 00:02:31] nenolod at dereferenced dot org Description: ------------ --- From manual page: http://www.php.net/function.hash-pbkdf2#refsect1-function.hash-pbkdf2-notes --- CRYPT_BLOWFISH has a limit of 76 characters maximum. PBKDF2 has no limit, and when used with an HMAC function like sha256 or sha512 is vastly more complex to crack. Please consider removing this from the documentation as it recommends a poor security practise as 'superior'. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=64816&edit=1

« previous php.doc.bugs (#10022) next »