Doc #76290 [Opn]: Wrong info in argon2i memory_cost
| From: | redir1 at npn dot fi | Date: | Mon, 30 Apr 2018 15:48:56 +0000 |
| Subject: | Doc #76290 [Opn]: Wrong info in argon2i memory_cost | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-15633@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76290&edit=1
ID: 76290
User updated by: redir1 at npn dot fi
Reported by: redir1 at npn dot fi
Summary: Wrong info in argon2i memory_cost
Status: Open
Type: Documentation Problem
Package: Documentation problem
Operating System: N/A
PHP Version: 7.2.5
Block user comment: N
Private report: N
New Comment:
Expected and actual results got mixed up, but the info remains the same.
Previous Comments:
------------------------------------------------------------------------
[2018-04-30 15:45:43] redir1 at npn dot fi
Description:
------------
---
From manual page: http://www.php.net/function.password-hash
---
The manual page says:
"memory_cost (integer) - Maximum memory (in bytes) that may be used to compute the Argon2 hash.
Defaults to PASSWORD_ARGON2_DEFAULT_MEMORY_COST."
The memory in reality is in kilobytes, not bytes. Confirmed by testing the memory usage, execution
speed and also by reading the source code.
Test script:
---------------
password_hash('passu', PASSWORD_ARGON2I, [
'memory_cost' => 1024 * 1024, // According to documentation, should be 1MB
'time_cost' => 4,
'threads' => 2,
]);
Expected result:
----------------
Check the memory usage of the script. It's 1GB.
Actual result:
--------------
Memory usage should not be a lot more than 1MB.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76290&edit=1