Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
| From: | Mirco Babin | Date: | Thu, 08 Oct 2026 18:04:33 +0000 |
| Subject: | Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132838@lists.php.net to get a copy of this message | ||
Hello Sjoerd Langkemper,
>I propose to add a new hashing algorithm to use in password_hash and
>password_verify.
>
>RFC: https://wiki.php.net/rfc/bcrypt_sha256
>PR: https://github.com/php/php-src/pull/24073
I have 3 comments.
=================
Begin of comments
=================
The RFC states:
>Rather than inventing a new, PHP-specific pre-hashing scheme, this
>RFC proposes adopting an existing, well-reviewed and widely deployed
>one: Passlib's bcrypt_sha256 hash, in its current “version 2” form
>(the default since Passlib 1.7.3).
=========
Comment 1
=========
Who invented the *bcrypt_sha256 hash* specification? In what
official specification, IETF-RFC, NIST-specification is it described?
Passlib is not a trusted source for security related issues. Passlib
is a library that only implements things, that might or might not be
backed by an official security specification.
=========
Comment 2
=========
Why is something proposed that goes *against OWASP* recommendations?
OWASP states, see
https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet..html#pre-hashing-passwords-with-bcrypt
>To summarize if bcrypt has to be used and the password should to be
>pre-hashed you should do
>bcrypt(base64(hmac-sha384(data:$password, key:$pepper)), $salt, $cost)
>and store the pepper not in the database.
=========
Comment 3
=========
Is interoperability with other systems considered?
For example assume a C# application and a PHP application sharing
the same database for user credentials. Is this going to work out
of the C# box with this invented algorithm? Or has the C# side to do
all kinds of security sensitive programming to implement this
algorithm?
The same question for Delphi, Javascript and other languages.
===============
End of comments
===============
Kind regards,
Mirco Babin