Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
| From: | Jordi Kroon | Date: | Thu, 01 Oct 2026 12:55:03 +0000 |
| Subject: | Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132746@lists.php.net to get a copy of this message | ||
On 01/10/2026 12:11 am, Derick Rethans wrote:
On 30 September 2026 22:26:21 BST, "Tim Düsterhus" <tim@bastelstu.be> wrote:
If a user of a site has a silly long password now, they can still login. If this changes to an Exception, then they no longer can, without intervention from a site owner, for whom there is now BC break in the language throwing random new exceptions *based on user input*.I agree with Derick's concerns. This change could affect users who chose long passwords because they believed they would be more secure. I don't believe those users should be \'affected. I support changing the default to argon2, but this change will be a -1 from me as well. -- Regards, Jordi Kroon