Re: Password_hash salt generation refactor
| From: | Tom Worster | Date: | Mon, 19 Oct 2015 15:22:04 +0000 |
| Subject: | Re: Password_hash salt generation refactor | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-88876@lists.php.net to get a copy of this message | ||
On 10/18/15 7:39 PM, Ángel González wrote:
Korvin wrote:A password salt needs to be unique. It does not need to be drawn from a CSPRNG but that is one of the few ways we can be reasonably confident of uniqueness (since, as usual, we assume the platform RNG is properly seeded). I can seed php_rand() from my script but, other than using the platform RNG, I have no idea how. Or I can let PHP seed it but its algorithm, a function of time and PID, shows PHP doesn't know how either. As PHP's version numbers increase, so should it's rigor in using best practices. I've no problem with apps breaking in the 5 -> 7 upgrade if they have no access to platform RNG. So doing Anthony's proposed change as early as possible in 7.0.x is best. Tom+1 for 7.0.x security patch release, best effort sounds scary.This is a salt. It doesn't need to be cryptographically secure. Using php_rand() there should pose no problem. I would actually include that into the patch (move old lines 154-156 into the FAILURE if).