Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash

From: Date: Mon, 05 Oct 2026 13:38:36 +0000
Subject: Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-132793@lists.php.net to get a copy of this message
Hi On 2026-10-05 15:25, Anton Smirnov wrote:
Hello, I propose to add a new hashing algorithm to use in password_hash and password_verify. RFC: https://wiki.php.net/rfc/bcrypt_sha256 <https://wiki.php.net/rfc/ bcrypt_sha256> PR: https://github.com/php/php-src/pull/24073 <https://github.com/php/ php-src/pull/24073>
It appears to me like it needs a rounds config and a PASSWORD_BCRYPT_SHA256_DEFAULT_ROUNDS constant, so we can have // be extra secure password_hash($password, PASSWORD_BCRYPT_SHA256, [
    "cost" => PASSWORD_BCRYPT_SHA256_DEFAULT_COST + 2,
    "rounds" => PASSWORD_BCRYPT_SHA256_DEFAULT_ROUNDS + 2,
];
rounds and cost are the same thing. The format calls it rounds, but the PHP API calls it cost. Keeping cost on the PHP API makes sense to me for consistency with PASSWORD_BCRYPT, even if it is inconsistent with the hash string. Best regards Tim Düsterhus

« previous php.internals (#132793) next »