Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt

From: Date: Fri, 02 Oct 2026 18:41:57 +0000
Subject: Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14  Groups: php.internals 
Request: Send a blank email to internals+get-132776@lists.php.net to get a copy of this message
Hi On 2026-10-01 13:02, Sjoerd Langkemper wrote:
However, I was under the impression that this was problematic, seeing the lack of progress on yescrypt. Perhaps bcrypt-sha256 is different since we already have both fundamental functions built in?
The problems are with including extra libraries. A minimal build of PHP should be possible without installing any extra libraries, which means that libraries are vendored into php-src as necessary. This comes with the usual problems of vendoring, such as keeping libraries up to date. Yescrypt likely doesn't provide enough benefit for the extra maintenance effort. For bcrypt-sha256 this situation is different, since all the necessary primitives are already always-available. For reference to the other readers, Sjoerd already opened a PR with an implementation: https://github.com/php/php-src/pull/24073. There are some technical nits, but I don't see anything fundamentally wrong with it. Best regards Tim Düsterhus

« previous php.internals (#132776) next »