Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
| From: | Sjoerd Langkemper | Date: | Thu, 01 Oct 2026 06:57:43 +0000 |
| Subject: | Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132739@lists.php.net to get a copy of this message | ||
On Thu, Oct 1, 2026, at 00:11, Derick Rethans wrote:
> The problem for me is that this a scary BC break.
Yes. I think the BC break is worth it, but I understand how opinions may differ on this.
> If this changes to an Exception, then they no longer can [login]
Sort of. I intentionally only proposed changing password_hash and not password_verify. However,
password_hash may still be used in the login flow, so login may fail for long passwords but this
depends on the application logic.
Is there anything you could think of that would improve the situation but would potentially have
your approval? First switch the default password hash from bcrypt to something else? Increase the
length at which an exception is thrown? Not an exception but a warning?
Regards,
Sjoerd