Re: PEAR Auth, File_Passwd, and crypt() limitation?
| From: | Tomas V.V.Cox | Date: | Wed, 13 Apr 2005 20:54:16 +0000 |
| Subject: | Re: PEAR Auth, File_Passwd, and crypt() limitation? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-37220@lists.php.net to get a copy of this message | ||
Paul M Jones wrote:
Hi, all, I've posted a blog entry about using crypt() with passwords longer than 8 characters here:As shown in the comments for php crypt(), if you don't supply a salt that limitation is not true. Modern versions of htpasswd use by default SHA a much serious algo than DES or MD5. Well, it seems that a chineese team have found some collitions in the SHA hashing algo, what could compromise it too. There are: 2^56 key space for DES 2^64 key space for MD5 2^80 key space for SHA1 DES is publically accepted as an insecure crypt algo, MD5 could be reduced to 2^32 and the SHA1 recent discoveries looks to lower its key space to 2^69. For understanding better the problem, for the NSA or any big cluster takes a week to crack a 2^69 key space (2^80 would take them 39 years). An interesting discussion about that could be found at: http://www.schneier.com/blog/archives/2005/02/sha1_broken.html Regards, Tomas V.V.Coxhttp://paul-m-jones.com/blog/?p=134I think File_Passwd (and thus indirectly the Cvs.php container for Auth) may be susceptible to this as well. Basically, crypt only checks the first 8 characters, so if the stored (crypted) password is "longpassword" and the user enters "longpass" it will be treated as a positive check. This is probably bad. However, I may have missed something that renders my point invalid; I leave it to those more learned than I to say. Comments? Criticism?