Doc #81473 [ReO->Csd]: hash_pbkdf2 truncate in hex
| From: | git@php.net | Date: | Mon, 27 Sep 2021 12:34:13 +0000 |
| Subject: | Doc #81473 [ReO->Csd]: hash_pbkdf2 truncate in hex | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-19228@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81473&edit=1
ID: 81473
Updated by: git@php.net
Reported by: php at wfuchs dot de
Summary: hash_pbkdf2 truncate in hex
-Status: Re-Opened
+Status: Closed
Type: Documentation Problem
Package: hash related
Operating System: Linux
PHP Version: 8.0.11
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb69
Revision: https://github.com/php/doc-en/commit/8ad9c12d9bf30c0a0c06f150643c0669d02c3125
Log: Fix #81473: hash_pbkdf2 truncate in hex
Previous Comments:
------------------------------------------------------------------------
[2021-09-25 15:58:13] requinix@php.net
How about we add a second example to the page showing how $binary and $length affect the return
value?
------------------------------------------------------------------------
[2021-09-25 15:43:43] requinix@php.net
> In my opinion this is a security related bug
It is always a security bug to call hashing functions without understanding how they should be used.
hash_pbkdf2 is a key derivation function. Its purpose is to generate a key that will presumably be
fed into something else of a cryptographic nature. That "something else" might want binary
bytes or it might want a hexit string. $length and $binary control hash_pbkdf2's output so a
developer doesn't have to do further work with substr/bin2hex/hex2bin to be able to use the
returned value as needed.
If you want a hexit string of length 128 (ie. 512 bits or two SHA256 hash blocks) then pass
$binary=false and $length=128. Which is what the documentation says.
------------------------------------------------------------------------
[2021-09-25 12:25:58] php at wfuchs dot de
I am addressing the part you posted:
"if binary is false this corresponds to twice the byte-length".
In my opinion this is a security related bug that weakens the cryptography and makes the
implementation incompatible to other languages:
256 different possibilities can be represented in one byte. That is 256^64 in binary form. Hexits
are only the numbers 0-9 and the letters A-F which makes a maximum of 16 possible hexits. Therefore
there are only 16^64 which is much less.
If you use 2 hexits per byte you get 16^2 which is 256 again.
------------------------------------------------------------------------
[2021-09-24 19:54:40] salathe@php.net
> The length in hex should be 128 and not 64 right?
No. The $length parameter dictates the length of the returned string. If you pass 64, the length of
the returned string will be 64.
------------------------------------------------------------------------
[2021-09-24 19:14:37] php at wfuchs dot de
The behavior the function describes
"if binary is false this corresponds to twice the byte-length of the derived key (as every byte
of the key is returned as two hexits)"
The length in hex should be 128 and not 64 right?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81473
--
Edit this bug report at https://bugs.php.net/bug.php?id=81473&edit=1