From 29a9d6ef8f1cb2e526fab9503a4e330af64f0543 Mon Sep 17 00:00:00 2001 From: johnnyq Date: Thu, 29 Dec 2022 18:23:11 -0500 Subject: [PATCH] Generate longer more secure Key for logins --- ajax.php | 4 ++-- api_key_add_modal.php | 2 +- blank.php | 5 +++++ functions.php | 16 ++++++++-------- login.php | 2 +- post.php | 4 ++-- 6 files changed, 19 insertions(+), 14 deletions(-) diff --git a/ajax.php b/ajax.php index c13fd60a..856e4402 100644 --- a/ajax.php +++ b/ajax.php @@ -239,8 +239,8 @@ if(isset($_GET['share_generate_link'])){ // Decrypt & re-encrypt password for sharing $login_password_cleartext = decryptLoginEntry($row['login_password']); - $login_encryption_key = keygen(); - $iv = keygen(); + $login_encryption_key = bin2hex(random_bytes(8)); + $iv = bin2hex(random_bytes(8)); $ciphertext = openssl_encrypt($login_password_cleartext, 'aes-128-cbc', $login_encryption_key, 0, $iv); $item_encrypted_credential = $iv . $ciphertext; diff --git a/api_key_add_modal.php b/api_key_add_modal.php index 8dc9d648..9253d568 100644 --- a/api_key_add_modal.php +++ b/api_key_add_modal.php @@ -1,5 +1,5 @@