Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
| From: | Sjoerd Langkemper | Date: | Wed, 30 Sep 2026 07:26:23 +0000 |
| Subject: | Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132706@lists.php.net to get a copy of this message | ||
On Tue, Sep 29, 2026, at 15:51, Tim Düsterhus wrote:
> The API is safe if you pass a “password” to it (as the name indicates).
> The issues described in the RFC were caused by folks passing something
> that is not a password.
Exactly, and my proposal aims to throw a ValueError in those cases, indicating that it is a
programming error to pass anything other than password. The tradeoff is that actual passwords longer
than 72 bytes are no longer supported. I think that is acceptable. I have gathered data showing that
such passwords are exceedingly rare. Also, if users genuinely need longer passwords, it is also not
defensible to silently truncate the password.
> The login will start to fail when the password is being rehashed
> (password_needs_rehash()) due to a change in the algorithm parameters
That is a good point, I had not considered that. Thanks.
Regards,
Sjoerd