Doc #81473 [ReO->Csd]: hash_pbkdf2 truncate in hex

From: Date: Mon, 27 Sep 2021 12:34:13 +0000
Subject: Doc #81473 [ReO->Csd]: hash_pbkdf2 truncate in hex
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-19228@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81473&edit=1 ID: 81473 Updated by: git@php.net Reported by: php at wfuchs dot de Summary: hash_pbkdf2 truncate in hex -Status: Re-Opened +Status: Closed Type: Documentation Problem Package: hash related Operating System: Linux PHP Version: 8.0.11 Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb69 Revision: https://github.com/php/doc-en/commit/8ad9c12d9bf30c0a0c06f150643c0669d02c3125 Log: Fix #81473: hash_pbkdf2 truncate in hex Previous Comments: ------------------------------------------------------------------------ [2021-09-25 15:58:13] requinix@php.net How about we add a second example to the page showing how $binary and $length affect the return value? ------------------------------------------------------------------------ [2021-09-25 15:43:43] requinix@php.net > In my opinion this is a security related bug It is always a security bug to call hashing functions without understanding how they should be used. hash_pbkdf2 is a key derivation function. Its purpose is to generate a key that will presumably be fed into something else of a cryptographic nature. That "something else" might want binary bytes or it might want a hexit string. $length and $binary control hash_pbkdf2's output so a developer doesn't have to do further work with substr/bin2hex/hex2bin to be able to use the returned value as needed. If you want a hexit string of length 128 (ie. 512 bits or two SHA256 hash blocks) then pass $binary=false and $length=128. Which is what the documentation says. ------------------------------------------------------------------------ [2021-09-25 12:25:58] php at wfuchs dot de I am addressing the part you posted: "if binary is false this corresponds to twice the byte-length". In my opinion this is a security related bug that weakens the cryptography and makes the implementation incompatible to other languages: 256 different possibilities can be represented in one byte. That is 256^64 in binary form. Hexits are only the numbers 0-9 and the letters A-F which makes a maximum of 16 possible hexits. Therefore there are only 16^64 which is much less. If you use 2 hexits per byte you get 16^2 which is 256 again. ------------------------------------------------------------------------ [2021-09-24 19:54:40] salathe@php.net > The length in hex should be 128 and not 64 right? No. The $length parameter dictates the length of the returned string. If you pass 64, the length of the returned string will be 64. ------------------------------------------------------------------------ [2021-09-24 19:14:37] php at wfuchs dot de The behavior the function describes "if binary is false this corresponds to twice the byte-length of the derived key (as every byte of the key is returned as two hexits)" The length in hex should be 128 and not 64 right? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81473 -- Edit this bug report at https://bugs.php.net/bug.php?id=81473&edit=1

« previous php.doc.bugs (#19228) next »