Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
| From: | Andrey Andreev | Date: | Thu, 08 Oct 2026 21:03:13 +0000 |
| Subject: | Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132840@lists.php.net to get a copy of this message | ||
Hi Sjoerd,
On Thu, Oct 8, 2026 at 9:37 PM Sjoerd Langkemper <sjoerd-php@linuxonly.nl>
wrote:
> Hi Mirco Babin,
>
> On Thu, Oct 8, 2026, at 20:04, Mirco Babin wrote:
>
> Passlib is not a trusted source for security related issues.
> Why is something proposed that goes *against OWASP* recommendations?
> Is interoperability with other systems considered?
>
>
> Thank you for your feedback. Do you have a suggestion for a password hash
> that is specified by a recognized organization and has better
> interoperability with other systems?
>
> I considered PBKDF2; it is widely supported and standardized by NIST, but
> it is generally seen as less secure than bcrypt. Would you prefer this,
> even if it is less resistant to offline cracking attacks?
>
You seem too eager to deliver on this, having vibe-coded the bcrypt-sha256
PR just a day after the idea was thrown in, and now asking for other
suggestions after first pushback.
These aren't good foundations for a major security feature, which will
reflect poorly on it even if you stumble upon the best possible solution.
I've been working on an alternative for weeks already and hope to be able
to put it up soon. Have a small blocker outside of my hands that may take
another week or two.
Please allow me some time before rushing in with another RFC.
Cheers,
Andrey.