Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
| From: | Mirco Babin | Date: | Fri, 09 Oct 2026 14:02:48 +0000 |
| Subject: | Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132855@lists.php.net to get a copy of this message | ||
Hello Sjoerd Langkemper,
(Mirco Babin)
>Passlib is not a trusted source for security related issues.
>Why is something proposed that goes *against OWASP* recommendations?
>Is interoperability with other systems considered?
(Sjoerd Langkemper)
>Thank you for your feedback. Do you have a suggestion for a password
>hash that is specified by a recognized organization and has better
>interoperability with other systems?
(Mirco Babin) This question is wrongly addressed to me. I have no
intention of writing a RFC.
(Sjoerd Langkemper)
>I considered PBKDF2; it is widely supported and standardized by NIST,
>but it is generally seen as less secure than bcrypt. Would you prefer
>this, even if it is less resistant to offline cracking attacks?
(Mirco Babin) My preference is of no importance. Also I don't have a
preference. Following security standards and interoperability is
what PHP should offer to its users, the programmers using PHP.
Kind regards,
Mirco Babin