Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
| From: | Anton Smirnov | Date: | Mon, 05 Oct 2026 13:25:53 +0000 |
| Subject: | Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132790@lists.php.net to get a copy of this message | ||
Hi Sjoerd!
On 05/10/2026 12:20, Sjoerd Langkemper wrote:
Hello, I propose to add a new hashing algorithm to use in password_hash and password_verify. RFC: https://wiki.php.net/rfc/bcrypt_sha256 <https://wiki.php.net/rfc/ bcrypt_sha256> PR: https://github.com/php/php-src/pull/24073 <https://github.com/php/ php-src/pull/24073>It appears to me like it needs a rounds config and a PASSWORD_BCRYPT_SHA256_DEFAULT_ROUNDS constant, so we can have // be extra secure password_hash($password, PASSWORD_BCRYPT_SHA256, [
"cost" => PASSWORD_BCRYPT_SHA256_DEFAULT_COST + 2,
"rounds" => PASSWORD_BCRYPT_SHA256_DEFAULT_ROUNDS + 2,
];
Otherwise I love the proposal
p.s. Resent. I forgot I should reply to the list, sorry
--
Anton