Re: crypt() BC issue

From: Date: Mon, 21 Jul 2014 09:44:59 +0000
Subject: Re: crypt() BC issue
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16  Groups: php.internals 
Request: Send a blank email to internals+get-75756@lists.php.net to get a copy of this message
Hi all, On Mon, Jul 21, 2014 at 3:17 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > In old days, crypt() was unusable securely. There are many > users/developers that > are used to have static slat. Code like below disables authentication > completely. > > password_hash(hash('sha512', SOME_SECRET_SALT).$password, DEFAULT); > > This should be prevented. (I would like to prevent it by raising E_NOTICE > error) > E_NOTICE for password larger than 72 is mandatory. Current password_hash() works without any sign of problem even if it may not be working as authentication. I'll add E_NOTICE as bug fix if there aren't any more comments. If we would like to recommend "Just use it", we may consider adding SHA512 > to password_hash(). > This one needs RFC, but I'm OK with prehashing in userland. Please write RFC and implement it if you are willing to have this. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#75756) next »