Doc #63549 [Opn->Wfx]: Wrong commentary
| From: | aharvey@php.net | Date: | Mon, 19 Nov 2012 04:41:52 +0000 |
| Subject: | Doc #63549 [Opn->Wfx]: Wrong commentary | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-9180@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=63549&edit=1
ID: 63549
Updated by: aharvey@php.net
Reported by: varnavruz at gmail dot com
Summary: Wrong commentary
-Status: Open
+Status: Wont fix
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
To quote Solar Designer in bug #55477:
"For practical purposes, it does not really matter if you use $2a$ or $2y$ for newly set
passwords, as the countermeasure is only triggered on some obscure passwords (not even valid UTF-8)
that are unlikely to be seen outside of a deliberate attack (trying to match hashes produced by
buggy pre-5.3.7 code)."
We've gone around on this a bit (prompted by earlier bugs such as doc bug #62414) â at
this point, the $2y$ recommendation seems like the best balance, since it retains the more secure
behaviour but also backward compatibility.
Previous Comments:
------------------------------------------------------------------------
[2012-11-17 15:35:29] varnavruz at gmail dot com
Description:
------------
---
From manual page: http://www.php.net/function.crypt#refsect1-function.crypt-
description
---
Page says:
Please refer to » this document for full details of the security fix, but to
summarise, developers targeting only PHP 5.3.7 and later should use "$2y$" in
preference to "$2a$".
But linked document (http://www.php.net/security/crypt_blowfish.php) says:
if the app prefers security and correctness over backwards compatibility, no
action is needed - just upgrade to new PHP and use its new behavior (with $2a$).
However, if an app install admin truly prefers backwards compatibility over
security, and the problem is seen on the specific install ... using $2y$ on
newly set passwords.
So, this means that manual recommends backwards compatibility over security, not
security and correctness over backwards compatibility for developers targeting
only PHP 5.3.7 and later.
Why developers targeting only PHP 5.3.7 and later shall worry about insecure
backwards compatibility?
Expected result:
----------------
Please remove the wrong recommendation to use $2y$ over $2a$
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=63549&edit=1