Re: PEAR Auth, File_Passwd, and crypt() limitation?

From: Date: Wed, 13 Apr 2005 22:57:30 +0000
Subject: Re: PEAR Auth, File_Passwd, and crypt() limitation?
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-37224@lists.php.net to get a copy of this message
Ian Eure wrote:
Basically, crypt only checks the first 8 characters, so if the stored (crypted) password is "longpassword" and the user enters "longpass" it will be treated as a positive check. This is probably bad. However, I may have missed something that renders my point invalid; I leave it to those more learned than I to say. Comments? Criticism?
This is a long-known limitation of the original UNIX crypt() implementation.
Clearly my own ignorance is the culprit, not the technology. However, if I am ignorant of what must be a very old issue, others may be too.
I think that some sort of warning should be put in the docs (and/or code), stating the limitations of crypt(). Perhaps a note to the effect that it's not recommended to use it for anything other than legacy compatibility.
I agree about the in-code warning, and there should probably be a bit of end-user documentation for it in the File_Passwd section ... Not to get off track -- http://pear.php.net/package/File_Passwd/docs provides a link to end-user documentation, but that link leads to the general file system documentation contents. Is there File_Passwd documentation? If so, this should probably be noted; if not, well, maybe the link should be changed.

« previous php.pear.dev (#37224) next »