[RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
| From: | Sjoerd Langkemper | Date: | Mon, 05 Oct 2026 09:20:29 +0000 |
| Subject: | [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-132784@lists.php.net to get a copy of this message | ||
Hello,
I propose to add a new hashing algorithm to use in password_hash and password_verify.
RFC: https://wiki.php.net/rfc/bcrypt_sha256
PR: https://github.com/php/php-src/pull/24073
The existing bcrypt has problems with null bytes and only hashes the first 72 bytes. The proposed
PASSWORD_BCRYPT_SHA256 algorithm solves those problems by first hashing the password with HMAC
SHA256 before passing it through bcrypt.
Tim suggested this in the discussion on my earlier RFC to throw errors on passwords longer than 72
bytes (https://wiki.php.net/rfc/bcrypt_max_password_length). That suggestion receives much criticism
because of its backwards incompatibility, and I don't think it is worth pursuing further at the
moment. I think this new hash is a gentler way to solve the underlying problem.
Regards,
Sjoerd Langkemper