Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt

From: Date: Thu, 01 Oct 2026 11:02:40 +0000
Subject: Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
References: 1 2 3 4 5 6 7 8 9 10 11 12 13  Groups: php.internals 
Request: Send a blank email to internals+get-132744@lists.php.net to get a copy of this message
On Thu, Oct 1, 2026, at 10:21, Tim Düsterhus wrote: > To provide a constructive suggestion: Borrowing passlib’s > bcrypt-sha256 > algorithm (including the output format) might be a valid option for a > well-defined pre-hashing solution. Yes, having another password hashing algorithm that does not truncate (like bcrypt) and is included by default (unlike argon2) would be great. However, I was under the impression that this was problematic, seeing the lack of progress on yescrypt. Perhaps bcrypt-sha256 is different since we already have both fundamental functions built in? yescrypt PR: https://github.com/php/php-src/pull/16452 Regards, Sjoerd

« previous php.internals (#132744) next »