Do not upgrade to PHP 5.3.7 due to a bug in crypt()
php.net
php.net
Interesting: Their build server has a failing test for crypt: http://gcov.php.net/viewer.php?version=PHP_5_3&func=test...
So I would assume that this should have been caught by running the tests before making the release. Or whoever ran the tests had them passing due to build artifacts of previous builds.
Or there are just too many tests that fail regularly: http://gcov.php.net/viewer.php?version=PHP_5_3&func=test... - when you have 201 failing tests, one more probably isn't going to cause any concern.
I couldn't find a page with automatic tests running against each implementations head/master branch. But I do see crypt() like specs in there: https://github.com/rubyspec/rubyspec.git
And here's one with just Python 2.7 on high-priority platforms: http://www.python.org/dev/buildbot/all/waterfall?category=2....
Of course, the packager for the distro should be running tests, and raising some serious questions when stuff fails.
This is a an open source project - anyone want to volunteer?
Now that I've made my confession, I think that this is the latest piece of evidence in a long line showing that the PHP core team just doesn't know how to program. See also this horrorshow that is the list of attempted fixes for an integer overflow vulnerability in 2007: http://use.perl.org/~Aristotle/journal/33448 and this complete freshman-level lack of comprehension of C: http://gnats.netbsd.org/cgi-bin/query-pr-single.pl?number=34.... And of course there are the evidences of incompetence permanently enshrined in the language, like the fact that "a ? b : c ? d : e" parses incorrectly as "(a ? b : c) ? d : e", but those could simply mean that Rasmus didn't know how to program when he was first designing PHP.
Nevertheless, it must be said that PHP is an incredibly useful piece of software. It clearly shows that intelligence and even basic programming competence are not sufficient or even necessary to build great software. You can do it on sisu alone, and without sisu you can't do it.
I'm serious. Without seeing this here, I might have used YUM to upgrade to the latest version (5.3.7) like I often do. I get the php-announce emails telling me that a new version is available, but nothing telling me when a problem like this emerges.
I think the answer is that this announcement should go out in php-announce. Maybe it will later today.
I'm sure there's something similar for Linux.
But that's me: I'd rather code in a quiet backwater (e.g. PHP in the future, when everyone has moved on) than be screaming along the cutting edge. Such a goal is definitely the opposite of many.
No, I'm not serious. But if everyone wakes up for a second, checks if they are vulnerable and maybe, accidentally stumbles upon 'Why you don't want to use MD5 for your authentication' posts.. Wouldn't the world be a better place tomorrow?
MCF is an ad-hoc cruft because the orginal crypt() is weak.
Anyway guess who did it :
"let's use strlcpy/strlcat instead for these static string copies" - Rasmus I guess that's Lerdorf himself
Whoever it was also didn't check the return values for error. Strlcat returns the length of the new string which might not be the same as strlen(dst) + strlen(src).
"I'm not a real programmer. I throw together things until it works then I move on." - Rasmus Lerdorf
Here's where he broke it : Sun Aug 7 16:10:34 2011 UTC http://svn.php.net/viewvc/php/php-src/trunk/ext/standard/php...
Here's it being fixed : Fri Aug 19 22:49:18 2011 UTC http://svn.php.net/viewvc/php/php-src/trunk/ext/standard/php...
[1] http://packages.python.org/passlib/modular_crypt_format.html
Tests, I'm in charge, I don't test.
Of course I don't want to advocate using MD5, even iterated a thousand times, for both of the reasons you state. There are better alternatives. scrypt appears to be one of them, and if it stands up to analysis, it's better than PBKDF2 and bcrypt, which in turn are better than MD5-crypt.
However, MD5 iterated 1000 times is still 1000 times better than MD5 iterated once (which an alarming number of codebases still use!) and the vulnerabilities that have been published in MD5 are not sufficient to speed up an attack on an MD5-crypted password file.
So MD5-crypt is still vastly preferable to many alternatives, including traditional Unix crypt(), even though MD5 has been broken and DES hasn't.