Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash

From: Date: Fri, 09 Oct 2026 14:02:48 +0000
Subject: Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-132855@lists.php.net to get a copy of this message
Hello Sjoerd Langkemper, (Mirco Babin) >Passlib is not a trusted source for security related issues. >Why is something proposed that goes *against OWASP* recommendations? >Is interoperability with other systems considered? (Sjoerd Langkemper) >Thank you for your feedback. Do you have a suggestion for a password >hash that is specified by a recognized organization and has better >interoperability with other systems? (Mirco Babin) This question is wrongly addressed to me. I have no intention of writing a RFC. (Sjoerd Langkemper) >I considered PBKDF2; it is widely supported and standardized by NIST, >but it is generally seen as less secure than bcrypt. Would you prefer >this, even if it is less resistant to offline cracking attacks? (Mirco Babin) My preference is of no importance. Also I don't have a preference. Following security standards and interoperability is what PHP should offer to its users, the programmers using PHP. Kind regards, Mirco Babin

« previous php.internals (#132855) next »