Re: Re: PEAR Auth, File_Passwd, and crypt() limitation?

From: Date: Thu, 14 Apr 2005 13:49:01 +0000
Subject: Re: Re: PEAR Auth, File_Passwd, and crypt() limitation?
References: 1 2  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-37234@lists.php.net to get a copy of this message
Then whirlpool might be considered[1]. [1]: http://planeta.terra.com.br/informatica/paulobarreto/WhirlpoolPage.html >> I've posted a blog entry about using crypt() with passwords longer >> than 8 characters here: >> >> http://paul-m-jones.com/blog/?p=134 >> >> I think File_Passwd (and thus indirectly the Cvs.php container for >> Auth) may be susceptible to this as well. >> >> Basically, crypt only checks the first 8 characters, so if the stored >> (crypted) password is "longpassword" and the user enters "longpass" it >> will be treated as a positive check. This is probably bad. >> >> However, I may have missed something that renders my point invalid; I >> leave it to those more learned than I to say. Comments? Criticism? > > > As shown in the comments for php crypt(), if you don't supply a salt > that limitation is not true. > > Modern versions of htpasswd use by default SHA a much serious algo than > DES or MD5. Well, it seems that a chineese team have found some > collitions in the SHA hashing algo, what could compromise it too. > > There are: > > 2^56 key space for DES > 2^64 key space for MD5 > 2^80 key space for SHA1 > > DES is publically accepted as an insecure crypt algo, MD5 could be > reduced to 2^32 and the SHA1 recent discoveries looks to lower its key > space to 2^69. > > For understanding better the problem, for the NSA or any big cluster > takes a week to crack a 2^69 key space (2^80 would take them 39 years). > > An interesting discussion about that could be found at: > http://www.schneier.com/blog/archives/2005/02/sha1_broken.html > > Regards, > > Tomas V.V.Cox >

« previous php.pear.dev (#37234) next »