Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash

From: Date: Mon, 05 Oct 2026 13:25:53 +0000
Subject: Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-132790@lists.php.net to get a copy of this message
Hi Sjoerd! On 05/10/2026 12:20, Sjoerd Langkemper wrote:
Hello, I propose to add a new hashing algorithm to use in password_hash and password_verify. RFC: https://wiki.php.net/rfc/bcrypt_sha256 <https://wiki.php.net/rfc/ bcrypt_sha256> PR: https://github.com/php/php-src/pull/24073 <https://github.com/php/ php-src/pull/24073>
It appears to me like it needs a rounds config and a PASSWORD_BCRYPT_SHA256_DEFAULT_ROUNDS constant, so we can have // be extra secure password_hash($password, PASSWORD_BCRYPT_SHA256, [
    "cost" => PASSWORD_BCRYPT_SHA256_DEFAULT_COST + 2,
    "rounds" => PASSWORD_BCRYPT_SHA256_DEFAULT_ROUNDS + 2,
]; Otherwise I love the proposal p.s. Resent. I forgot I should reply to the list, sorry -- Anton

« previous php.internals (#132790) next »