RE: [PHP-DEV] [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt

From: Date: Thu, 01 Oct 2026 21:17:42 +0000
Subject: RE: [PHP-DEV] [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.internals 
Request: Send a blank email to internals+get-132766@lists.php.net to get a copy of this message
-----Original Message----- From: Tim Düsterhus <tim@bastelstu.be> Sent: Wednesday, September 30, 2026 6:08 PM To: Rowan Tommins [IMSoP] <imsop.php@rwec.co.uk> Cc: internals@lists.php.net Subject: Re: [PHP-DEV] [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt >> It seems to me that refusing those inputs and alerting the developer >> to the limitation leaves the *overall system* more secure. > My expectation is that developers who are “alerted” to the limitation will just go with > whatever solution makes the error message go away the quickest instead of trying to understand the > impact ===== If that's the case, then the "throw" proposal is an obvious win. Developers who would do as you feel have an easy remedy. Those who are competent are warned of a significant security issue, that they can properly analyze and resolve. -Jeff

« previous php.internals (#132766) next »