Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
| From: | Tim Düsterhus | Date: | Mon, 05 Oct 2026 13:38:36 +0000 |
| Subject: | Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132793@lists.php.net to get a copy of this message | ||
Hi
On 2026-10-05 15:25, Anton Smirnov wrote:
Hello, I propose to add a new hashing algorithm to use in password_hash and password_verify. RFC: https://wiki.php.net/rfc/bcrypt_sha256 <https://wiki.php.net/rfc/ bcrypt_sha256> PR: https://github.com/php/php-src/pull/24073 <https://github.com/php/ php-src/pull/24073>It appears to me like it needs a rounds config and a PASSWORD_BCRYPT_SHA256_DEFAULT_ROUNDS constant, so we can have // be extra secure password_hash($password, PASSWORD_BCRYPT_SHA256, ["cost" => PASSWORD_BCRYPT_SHA256_DEFAULT_COST + 2, "rounds" => PASSWORD_BCRYPT_SHA256_DEFAULT_ROUNDS + 2,];
rounds and cost are the same thing. The format calls it rounds, but the PHP API calls it cost. Keeping cost on the PHP API makes sense to me for consistency with PASSWORD_BCRYPT, even if it is inconsistent with the hash string.
Best regards
Tim Düsterhus