Re: Re: PEAR Auth, File_Passwd, and crypt() limitation?
| From: | Arnaud Limbourg | Date: | Thu, 14 Apr 2005 13:49:01 +0000 |
| Subject: | Re: Re: PEAR Auth, File_Passwd, and crypt() limitation? | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-37234@lists.php.net to get a copy of this message | ||
Then whirlpool might be considered[1].
[1]: http://planeta.terra.com.br/informatica/paulobarreto/WhirlpoolPage.html
>> I've posted a blog entry about using crypt() with passwords longer
>> than 8 characters here:
>>
>> http://paul-m-jones.com/blog/?p=134
>>
>> I think File_Passwd (and thus indirectly the Cvs.php container for
>> Auth) may be susceptible to this as well.
>>
>> Basically, crypt only checks the first 8 characters, so if the stored
>> (crypted) password is "longpassword" and the user enters "longpass" it
>> will be treated as a positive check. This is probably bad.
>>
>> However, I may have missed something that renders my point invalid; I
>> leave it to those more learned than I to say. Comments? Criticism?
>
>
> As shown in the comments for php crypt(), if you don't supply a salt
> that limitation is not true.
>
> Modern versions of htpasswd use by default SHA a much serious algo than
> DES or MD5. Well, it seems that a chineese team have found some
> collitions in the SHA hashing algo, what could compromise it too.
>
> There are:
>
> 2^56 key space for DES
> 2^64 key space for MD5
> 2^80 key space for SHA1
>
> DES is publically accepted as an insecure crypt algo, MD5 could be
> reduced to 2^32 and the SHA1 recent discoveries looks to lower its key
> space to 2^69.
>
> For understanding better the problem, for the NSA or any big cluster
> takes a week to crack a 2^69 key space (2^80 would take them 39 years).
>
> An interesting discussion about that could be found at:
> http://www.schneier.com/blog/archives/2005/02/sha1_broken.html
>
> Regards,
>
> Tomas V.V.Cox
>