RE: [PHP-DEV] [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
| From: | Jeff Dafoe | Date: | Thu, 01 Oct 2026 21:17:42 +0000 |
| Subject: | RE: [PHP-DEV] [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132766@lists.php.net to get a copy of this message | ||
-----Original Message-----
From: Tim Düsterhus <tim@bastelstu.be>
Sent: Wednesday, September 30, 2026 6:08 PM
To: Rowan Tommins [IMSoP] <imsop.php@rwec.co.uk>
Cc: internals@lists.php.net
Subject: Re: [PHP-DEV] [RFC] Throw error for passwords longer than 72 bytes in password_hash() with
bcrypt
>> It seems to me that refusing those inputs and alerting the developer
>> to the limitation leaves the *overall system* more secure.
> My expectation is that developers who are “alerted” to the limitation will just go with
> whatever solution makes the error message go away the quickest instead of trying to understand the
> impact
=====
If that's the case, then the "throw" proposal is an obvious win. Developers who would
do as you feel have an easy remedy. Those who are competent are warned of a significant security
issue, that they can properly analyze and resolve.
-Jeff