Doc #80843 [NEW]: Remove examples from comments as they are invariably insecure
| From: | maarten dot bodewes at gmail dot com | Date: | Sun, 07 Mar 2021 11:38:06 +0000 |
| Subject: | Doc #80843 [NEW]: Remove examples from comments as they are invariably insecure | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-18622@lists.php.net to get a copy of this message | ||
From: maarten dot bodewes at gmail dot com
Operating system:
PHP version: 8.0.3
Package: OpenSSL related
Bug Type: Documentation Problem
Bug description:Remove examples from comments as they are invariably insecure
Description:
------------
---
From manual page: https://php.net/function.openssl-encrypt
---
Remove examples from the comments sections of the OpenSSL libraries as
they are invariably insecure.
Here the most upvoted example for some reason uses SHA3 for HMAC, which
is unnecessarily strong and very slow compared to e.g. SHA-256. Much
worse is that the IV is not included in the HMAC calculation, which
means an attacker can change each of the initial 16 bytes at will. The
problem is that I can leave a comment, but it will take years before it
gets noticed.
Please remove all those examples from security functions because
COPY/PASTE security doesn't exist. At least not from unknown sources
that for some reason get upvoted and can never be retracted. Comments
should only be applicable to the function itself.
Please write the sample code yourself and have it reviewed by a security
professional because the authors of the OpenSSL library clearly are not
very capable either; if you confuse passwords and keys then you've got
some things to learn yet.
I'm Maarten Bodewes. I've corrected (terrible) examples of
mcrypt_encrypt before and indicated that mcrypt was insecure and
unmaintained. I'm #1 user for the cryptography tags at StackOverflow and
mod at the cryptography site of StackExchange.
--
Edit bug report at https://bugs.php.net/bug.php?id=80843&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=80843&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=80843&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=80843&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=80843&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=80843&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=80843&r=support
Expected behavior: https://bugs.php.net/fix.php?id=80843&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=80843&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=80843&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=80843&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80843&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=80843&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=80843&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=80843&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=80843&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=80843&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=80843&r=mysqlcfg