CryptographicallySecureAlgorithms
error on by defaultGroup: Security · PhpStorm name: CryptographicallySecureAlgorithmsInspection
Some cipher/hash selector constants of mcrypt, OpenSSL and crypt() pick algorithms that are broken or weak (DES, 3DES, RC2, RC4, MD5) or that are commonly mistaken for AES (Rijndael with 192/256-bit blocks). Point at each use so a stronger algorithm can be chosen.
Example
php
<?php
namespace Vault;
final class Sealer
{
public function seal($key, $data)
{
$legacy = mcrypt_encrypt(MCRYPT_TRIPLEDES, $key, $data, 'cbc');
$wide = [\MCRYPT_RIJNDAEL_256];
if (CRYPT_MD5 === 1) {
return openssl_encrypt($data, 'aes-128-gcm', $key);
}
return [$legacy, $wide, MCRYPT_RIJNDAEL_128, CRYPT_BLOWFISH, OPENSSL_ALGO_SHA1];
}
}
class CipherMatrixTest
{
public function provider()
{
return [MCRYPT_DES, OPENSSL_CIPHER_RC2_40];
}
}Reported:
- line 8: Weak algorithm selected via MCRYPT_TRIPLEDES (3DES); prefer MCRYPT_RIJNDAEL_128.
- line 9: Weak algorithm selected via MCRYPT_RIJNDAEL_256 (Rijndael with a 256-bit block is not AES); prefer MCRYPT_RIJNDAEL_128 with a 256-bit key.
- line 10: Weak algorithm selected via CRYPT_MD5 (MD5); prefer CRYPT_BLOWFISH.
Configure
In custos.json:
json
{
"rules": {
"CryptographicallySecureAlgorithms": {
"enabled": false
}
}
}Suppress
Before the statement or declaration (or the first statement of the file), either of:
php
// @custos-ignore CryptographicallySecureAlgorithms
/**
* @noinspection CryptographicallySecureAlgorithmsInspection
*/