Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt

From: Date: Wed, 30 Sep 2026 07:26:23 +0000
Subject: Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-132706@lists.php.net to get a copy of this message
On Tue, Sep 29, 2026, at 15:51, Tim Düsterhus wrote: > The API is safe if you pass a “password” to it (as the name indicates). > The issues described in the RFC were caused by folks passing something > that is not a password. Exactly, and my proposal aims to throw a ValueError in those cases, indicating that it is a programming error to pass anything other than password. The tradeoff is that actual passwords longer than 72 bytes are no longer supported. I think that is acceptable. I have gathered data showing that such passwords are exceedingly rare. Also, if users genuinely need longer passwords, it is also not defensible to silently truncate the password. > The login will start to fail when the password is being rehashed > (password_needs_rehash()) due to a change in the algorithm parameters That is a good point, I had not considered that. Thanks. Regards, Sjoerd

« previous php.internals (#132706) next »