Re: [Discussion] Changing PASSWORD_DEFAULT to Argon2
| From: | Andrey Andreev | Date: | Mon, 21 Sep 2026 18:42:54 +0000 |
| Subject: | Re: [Discussion] Changing PASSWORD_DEFAULT to Argon2 | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132584@lists.php.net to get a copy of this message | ||
Hi Tim,
On Mon, Sep 21, 2026 at 8:11 PM Tim Düsterhus <tim@bastelstu.be> wrote:
>
> 500ms is insanely long for interactive authentication. And the memory
> cost in that example benchmark is indeed scary when you consider that
> PHP ships with a default memory_limit of 128 MB (though it seems that
> the Argon2 hashing is not included in the memory_limit accounting).
That's missing the point I was making ...
The cited 1000ms had at least halved in 4 years (if the screenshot was up
to date at the time), and it's been an additional 3 years since.
Hashcat didn't even ship with Argon2 support until last year, so verifying
the benchmarks (if they are direct and not math projections) was extremely
hard.
PHP's defaults are m=64mb,t=4,p=1, which averages around 240ms on my 10y
laptop, same as bcrypt cost 12.
When Hashcat 7 did release last year it came with a benchmark for
m=64mb,t=3,p=1 yielding around 1.7k hashes per second:
https://hashcat.net/wiki/doku.php?id=hashcat
For bcrypt cost=12 I've seen rates ranging from 1k to 2k H/s using the same
GPU model (some variance in setups/optimizations I guess).
All of this is comparing ceilings well beyond safe recommendations,
somewhat like top speeds on a racing car; there's a solid argument that
e.g. 48mb or even 32mb is plenty enough.
But anyway, if Jakub's comment was describing the status-quo, it's just not
happening.
Cheers,
Andrey.