Skip to content

CryptographicallySecureAlgorithms ​

error on by default

Group: Security · PhpStorm name: CryptographicallySecureAlgorithmsInspection

Some cipher/hash selector constants of mcrypt, OpenSSL and crypt() pick algorithms that are broken or weak (DES, 3DES, RC2, RC4, MD5) or that are commonly mistaken for AES (Rijndael with 192/256-bit blocks). Point at each use so a stronger algorithm can be chosen.

Example ​

php
<?php
namespace Vault;

final class Sealer
{
    public function seal($key, $data)
    {
        $legacy = mcrypt_encrypt(MCRYPT_TRIPLEDES, $key, $data, 'cbc');
        $wide   = [\MCRYPT_RIJNDAEL_256];
        if (CRYPT_MD5 === 1) {
            return openssl_encrypt($data, 'aes-128-gcm', $key);
        }
        return [$legacy, $wide, MCRYPT_RIJNDAEL_128, CRYPT_BLOWFISH, OPENSSL_ALGO_SHA1];
    }
}

class CipherMatrixTest
{
    public function provider()
    {
        return [MCRYPT_DES, OPENSSL_CIPHER_RC2_40];
    }
}

Reported:

  • line 8: Weak algorithm selected via MCRYPT_TRIPLEDES (3DES); prefer MCRYPT_RIJNDAEL_128.
  • line 9: Weak algorithm selected via MCRYPT_RIJNDAEL_256 (Rijndael with a 256-bit block is not AES); prefer MCRYPT_RIJNDAEL_128 with a 256-bit key.
  • line 10: Weak algorithm selected via CRYPT_MD5 (MD5); prefer CRYPT_BLOWFISH.

Configure ​

In custos.json:

json
{
  "rules": {
    "CryptographicallySecureAlgorithms": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore CryptographicallySecureAlgorithms

/**
 * @noinspection CryptographicallySecureAlgorithmsInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.