Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
| From: | Sjoerd Langkemper | Date: | Thu, 01 Oct 2026 11:02:40 +0000 |
| Subject: | Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132744@lists.php.net to get a copy of this message | ||
On Thu, Oct 1, 2026, at 10:21, Tim Düsterhus wrote:
> To provide a constructive suggestion: Borrowing passlib’s
>
bcrypt-sha256
> algorithm (including the output format) might be a valid option for a
> well-defined pre-hashing solution.
Yes, having another password hashing algorithm that does not truncate (like bcrypt) and is included
by default (unlike argon2) would be great.
However, I was under the impression that this was problematic, seeing the lack of progress on
yescrypt. Perhaps bcrypt-sha256 is different since we already have both fundamental functions built
in?
yescrypt PR: https://github.com/php/php-src/pull/16452
Regards,
Sjoerd