Sec Bug->Doc #64537 [Asn->Csd]: Key is truncated for password_hash/crypt
| From: | nikic@php.net | Date: | Mon, 16 Jan 2017 14:41:22 +0000 |
| Subject: | Sec Bug->Doc #64537 [Asn->Csd]: Key is truncated for password_hash/crypt | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-14355@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=64537&edit=1
ID: 64537
Updated by: nikic@php.net
Reported by: lekensteyn at gmail dot com
Summary: Key is truncated for password_hash/crypt
-Status: Assigned
+Status: Closed
-Type: Security
+Type: Documentation Problem
Package: *Encryption and hash functions
Operating System: Linux x86_64
PHP Version: 5.5.0beta1
Assigned To: ircmaxell
Block user comment: N
Private report: Y
New Comment:
It looks like this has been documented in the meantime, so closing here.
Previous Comments:
------------------------------------------------------------------------
[2013-03-29 16:40:57] ircmaxell@php.net
Any code-level "fix" would break compatibility with crypt(3). Which I'm not
comfortable doing.
With that said, I agree that it should be documented. I'll add a warning against
that.
Additionally, considering this "bug" effects crypt(3) in its entirety, perhaps
it should be raised there, so a standard solution could be found (or agreed upon
that it's minor enough to not worry about). If we can get the crypt() community
to agree on a fix, I'd be happy to participate on that discussion.
------------------------------------------------------------------------
[2013-03-28 11:53:51] lekensteyn at gmail dot com
Description:
------------
While using password_hash() and password_verify() (using the compat library from ircmaxwell[0] on
PHP 5.4), I noticed that two passwords passed the test while those are really different.
It turns out that blowfish limits the length of the key to 72 bytes which is also stated in the
modified manual page of crypt(3) [1]. This limitation is not documented anywhere and poses a risk to
those who assume that the key length is unlimited.
Documentation that must be updated:
- crypt
- password_hash and password_verify
- hash_pbkdf2 (since you recommend using crypt+bf instead, it should also tell the difference)
Affected versions:
- 5.3.10-1ubuntu3.6 (Ubuntu 12.04 x86_64)
- 5.4.13-2 (Arch Linux x86_64)
- 5.5.0beta2 (Arch Linux x86_64, built with ./configure --without-pear)
I marked 5.5.0beta1 as affected as there is no beta2. Actually, all versions that use crypt+blowfish
are affected. A suggestion was made to run a hash function such as sha256 on the input string and
then proceed with bcrypt [2].
scrypt and pbkdf2 do not seem to expose this issue.
[0]: https://github.com/ircmaxell/password_compat
[1]: http://www.openwall.com/crypt/
[2]: http://security.stackexchange.com/q/6623/2630
Test script:
---------------
<?php
$key1 = str_repeat("x", 72);
$key2 = $key1 . "x";
$hash = password_hash($key1, PASSWORD_DEFAULT);
if (password_verify($key2, $hash)) {
echo "FAILED\n";
} else {
echo "PASSED\n";
}
Expected result:
----------------
PASSED
Actual result:
--------------
FAILED
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=64537&edit=1