Doc #69230 [Asn->Csd]: password_verify should indicate whether it's vulnerable to timing attacks
| From: | peehaa@php.net | Date: | Thu, 25 Jun 2015 11:30:32 +0000 |
| Subject: | Doc #69230 [Asn->Csd]: password_verify should indicate whether it's vulnerable to timing attacks | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12473@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69230&edit=1
ID: 69230
Updated by: peehaa@php.net
Reported by: brian at access9 dot net
Summary: password_verify should indicate whether it's
vulnerable to timing attacks
-Status: Assigned
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
PHP Version: 5.5.22
Assigned To: peehaa
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Previous Comments:
------------------------------------------------------------------------
[2015-03-12 15:00:10] brian at access9 dot net
Description:
------------
---
From manual page: http://www.php.net/function.password-verify
---
The documentation for the hash_verify() function (http://php.net/manual/en/function.hash-equals.php)
clearly states that it is a "Timing attack safe string comparison".
The documentation for password_verify() should indicate whether it is or is not vulnerable to timing
based attacks.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69230&edit=1