Re: crypt() BC issue
| From: | Yasuo Ohgaki | Date: | Mon, 21 Jul 2014 09:44:59 +0000 |
| Subject: | Re: crypt() BC issue | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75756@lists.php.net to get a copy of this message | ||
Hi all,
On Mon, Jul 21, 2014 at 3:17 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> In old days, crypt() was unusable securely. There are many
> users/developers that
> are used to have static slat. Code like below disables authentication
> completely.
>
> password_hash(hash('sha512', SOME_SECRET_SALT).$password, DEFAULT);
>
> This should be prevented. (I would like to prevent it by raising E_NOTICE
> error)
>
E_NOTICE for password larger than 72 is mandatory. Current password_hash()
works without any sign of problem even if it may not be working as
authentication.
I'll add E_NOTICE as bug fix if there aren't any more comments.
If we would like to recommend "Just use it", we may consider adding SHA512
> to password_hash().
>
This one needs RFC, but I'm OK with prehashing in userland.
Please write RFC and implement it if you are willing to have this.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net