Re: [RFC] Throw error for passwords lo nger than 72 bytes in password_hash() with bcrypt
| From: | Derick Rethans | Date: | Wed, 30 Sep 2026 22:11:47 +0000 |
| Subject: | Re: [RFC] Throw error for passwords lo nger than 72 bytes in password_hash() with bcrypt | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132735@lists.php.net to get a copy of this message | ||
On 30 September 2026 22:26:21 BST, "Tim Düsterhus" <tim@bastelstu.be> wrote:
>
>Even with a non-ASCII 2-byte per character diceware password you are at roughly 50 bits of
>entropy in the 72 bytes, which makes the math...
I don't think there maths and entropy etc, is the major problem for me with this proposal.
The problem for me is that this a scary BC break.
If a user of a site has a silly long password now, they can still login. If this changes to an
Exception, then they no longer can, without intervention from a site owner, for whom there is now BC
break in the language throwing random new exceptions *based on user input*.
I'm going to be -1 on this one.
cheers
Derick