Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
| From: | Sjoerd Langkemper | Date: | Thu, 08 Oct 2026 18:34:31 +0000 |
| Subject: | Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132839@lists.php.net to get a copy of this message | ||
Hi Mirco Babin,
On Thu, Oct 8, 2026, at 20:04, Mirco Babin wrote:
> Passlib is not a trusted source for security related issues.
> Why is something proposed that goes *against OWASP* recommendations?
> Is interoperability with other systems considered?
Thank you for your feedback. Do you have a suggestion for a password hash that is specified by a
recognized organization and has better interoperability with other systems?
I considered PBKDF2; it is widely supported and standardized by NIST, but it is generally seen as
less secure than bcrypt. Would you prefer this, even if it is less resistant to offline cracking
attacks?
Regards,
Sjoerd Langkemper