Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash

From: Date: Thu, 08 Oct 2026 18:04:33 +0000
Subject: Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-132838@lists.php.net to get a copy of this message
Hello Sjoerd Langkemper, >I propose to add a new hashing algorithm to use in password_hash and >password_verify. > >RFC: https://wiki.php.net/rfc/bcrypt_sha256 >PR: https://github.com/php/php-src/pull/24073 I have 3 comments. ================= Begin of comments ================= The RFC states: >Rather than inventing a new, PHP-specific pre-hashing scheme, this >RFC proposes adopting an existing, well-reviewed and widely deployed >one: Passlib's bcrypt_sha256 hash, in its current “version 2” form >(the default since Passlib 1.7.3). ========= Comment 1 ========= Who invented the *bcrypt_sha256 hash* specification? In what official specification, IETF-RFC, NIST-specification is it described? Passlib is not a trusted source for security related issues. Passlib is a library that only implements things, that might or might not be backed by an official security specification. ========= Comment 2 ========= Why is something proposed that goes *against OWASP* recommendations? OWASP states, see https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet..html#pre-hashing-passwords-with-bcrypt >To summarize if bcrypt has to be used and the password should to be >pre-hashed you should do >bcrypt(base64(hmac-sha384(data:$password, key:$pepper)), $salt, $cost) >and store the pepper not in the database. ========= Comment 3 ========= Is interoperability with other systems considered? For example assume a C# application and a PHP application sharing the same database for user credentials. Is this going to work out of the C# box with this invented algorithm? Or has the C# side to do all kinds of security sensitive programming to implement this algorithm? The same question for Delphi, Javascript and other languages. =============== End of comments =============== Kind regards, Mirco Babin

« previous php.internals (#132838) next »