Doc #78608 [Com]: Security error in documentation

From: Date: Wed, 02 Oct 2019 17:00:40 +0000
Subject: Doc #78608 [Com]: Security error in documentation
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-16981@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78608&edit=1

 ID:                 78608
 Comment by:         henry dot paradiz at gmail dot com
 Reported by:        gcleaves at gmail dot com
 Summary:            Security error in documentation
 Status:             Open
 Type:               Documentation Problem
 Package:            *Encryption and hash functions
 Operating System:   n/a
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

Just to confirm: you do understand that HMAC is no longer supported by PHP; therefore, we must use
CBC with message|key. In addition, because we are now using the CBC standard we no longer need to
worry about the IV. MD5 and Sha-1 are really what did it out with HMAC, highly crackable, highly
incorrect. You can use the following line of code as a replacement:

<?php 

if( 1==1 ) {

$password = 'plainText';

$cbc = hash_cbc('sha256', $password);

echo $cbc.$password; 

} else {

// do HMAC (in an older PHP version like 5.3)
}


?>


Previous Comments:
------------------------------------------------------------------------
[2019-09-29 07:41:33] gcleaves at gmail dot com

Description:
------------
---
From manual page: https://php.net/function.openssl-encrypt
---
Please note that at the time of writing this, there is an important and naive security vulnerability
in "Example #2 AES Authenticated Encryption example for PHP 5.6+".

You MUST include the IV when calculating the HMAC. Otherwise, somebody could alter the IV during
transport, thereby changing the decrypted message while maintaining HMAC integrity. An absolute
disaster.

To fix the example, the HMAC should be calculated like this:

<?php
$hmac = hash_hmac('sha256', $iv.$ciphertext_raw, $key, $as_binary=true);
?>

And to confirm the HMAC later:

<?php
$calcmac = hash_hmac('sha256', $iv.$ciphertext_raw, $key, $as_binary=true);
?>



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=78608&edit=1


Thread (3 messages)

« previous php.doc.bugs (#16981) next »