Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash

From: Date: Thu, 08 Oct 2026 21:03:13 +0000
Subject: Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-132840@lists.php.net to get a copy of this message
Hi Sjoerd, On Thu, Oct 8, 2026 at 9:37 PM Sjoerd Langkemper <sjoerd-php@linuxonly.nl> wrote: > Hi Mirco Babin, > > On Thu, Oct 8, 2026, at 20:04, Mirco Babin wrote: > > Passlib is not a trusted source for security related issues. > Why is something proposed that goes *against OWASP* recommendations? > Is interoperability with other systems considered? > > > Thank you for your feedback. Do you have a suggestion for a password hash > that is specified by a recognized organization and has better > interoperability with other systems? > > I considered PBKDF2; it is widely supported and standardized by NIST, but > it is generally seen as less secure than bcrypt. Would you prefer this, > even if it is less resistant to offline cracking attacks? > You seem too eager to deliver on this, having vibe-coded the bcrypt-sha256 PR just a day after the idea was thrown in, and now asking for other suggestions after first pushback. These aren't good foundations for a major security feature, which will reflect poorly on it even if you stumble upon the best possible solution. I've been working on an alternative for weeks already and hope to be able to put it up soon. Have a small blocker outside of my hands that may take another week or two. Please allow me some time before rushing in with another RFC. Cheers, Andrey.

« previous php.internals (#132840) next »