Doc #64816 [Fbk->Opn]: CRYPT_BLOWFISH is not better than PBKDF2
| From: | nenolod at dereferenced dot org | Date: | Tue, 05 May 2015 04:34:30 +0000 |
| Subject: | Doc #64816 [Fbk->Opn]: CRYPT_BLOWFISH is not better than PBKDF2 | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12294@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=64816&edit=1
ID: 64816
User updated by: nenolod at dereferenced dot org
Reported by: nenolod at dereferenced dot org
Summary: CRYPT_BLOWFISH is not better than PBKDF2
-Status: Feedback
+Status: Open
Type: Documentation Problem
Package: hash related
Operating System: N/A
PHP Version: 5.5.0RC1
Block user comment: N
Private report: N
New Comment:
It is not sufficient because it is wrong. Recommending a dubious homegrown password hashing
solution instead of a standard one (PBKDF2) is also dubious in and of itself, even if the
cryptographic primitives are correct.
The text should recommend that the PBKDF2 functions be used by "advanced" users (since the
cryptographic primitives used are configurable), and password_hash() should use PBKDF2 with at least
128,000 rounds or more which is standard practice, *not* CRYPT_BLOWFISH.
PHP is an overgrown templating engine not a cryptography research toolkit, it should be using
standardized best practices for password security.
Previous Comments:
------------------------------------------------------------------------
[2015-05-04 18:03:58] cmb@php.net
The respective info in the manual has been changed in the
meantime:
| The PBKDF2 method can be used for hashing passwords for storage.
| However, it should be noted that password_hash() or crypt() with
| CRYPT_BLOWFISH are better suited for password storage.
Is that sufficient?
------------------------------------------------------------------------
[2013-06-28 06:57:58] yohgaki@php.net
From the manual
==================
Caution
The PBKDF2 method can be used for hashing passwords for storage (it is NIST
approved for that use). However, it should be noted that CRYPT_BLOWFISH is
better suited for password storage and should be used instead via crypt().
==================
This is too much. There are several problems.
1. crypt() is not encouraged, password_hash() is. (PHP 5.5>=)
2. PHP 5.5 users are encouraged to use password_hash() since it allows to
upgrade hashing algorithm by upgrading PHP. (i.e. automatically updates
algorithm)
3. Both password_hash() and hash_pbkdf2() are good enough if users used them
with correct parameters.
Note that correct usage is important for robust security. RFC 2898 suggest 1000+
rounds and NIST suggests several thousands rounds with SHA2 hashing. However,
these number may consider too few with current technology.
http://security.stackexchange.com/questions/3959/recommended-of-iterations-when-
using-pkbdf2-sha256
It recommends tens of thousands rounds with SHA2 hash.
Anyway, both password_hash(), which uses crypt+blowfish internally, and
hash_pbkdf2() good enough if users set at least 10000 rounds with SHA2 hash. (I
would recommend 20000+, though)
I know there are number of weaknesses of blowfish have been reported, but it
wouldn't be a problem with password length longer than 8 chars (I would
recommend at least 10. 12+ is better)
Current password_hash() uses a little few rounds(2^10 = 1024). Since hash
computation execution efficiency is differ from SHA2, blowfish requires less
rounds and 1024 is acceptable, IMO. (I would suggest 2^12 or more, though)
Anyway, many users don't have clue about password hashing and current
documentation cannot consider correct. Doc should be updated.
------------------------------------------------------------------------
[2013-05-11 00:02:31] nenolod at dereferenced dot org
Description:
------------
---
From manual page: http://www.php.net/function.hash-pbkdf2#refsect1-function.hash-pbkdf2-notes
---
CRYPT_BLOWFISH has a limit of 76 characters maximum. PBKDF2 has no limit, and when used with an
HMAC function like sha256 or sha512 is vastly more complex to crack.
Please consider removing this from the documentation as it recommends a poor security practise as
'superior'.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=64816&edit=1