Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
| From: | Tim Düsterhus | Date: | Fri, 02 Oct 2026 18:41:57 +0000 |
| Subject: | Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132776@lists.php.net to get a copy of this message | ||
Hi
On 2026-10-01 13:02, Sjoerd Langkemper wrote:
However, I was under the impression that this was problematic, seeing the lack of progress on yescrypt. Perhaps bcrypt-sha256 is different since we already have both fundamental functions built in?The problems are with including extra libraries. A minimal build of PHP should be possible without installing any extra libraries, which means that libraries are vendored into php-src as necessary. This comes with the usual problems of vendoring, such as keeping libraries up to date. Yescrypt likely doesn't provide enough benefit for the extra maintenance effort. For bcrypt-sha256 this situation is different, since all the necessary primitives are already always-available. For reference to the other readers, Sjoerd already opened a PR with an implementation: https://github.com/php/php-src/pull/24073. There are some technical nits, but I don't see anything fundamentally wrong with it. Best regards Tim Düsterhus