Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
| From: | Mirco Babin | Date: | Fri, 09 Oct 2026 14:03:11 +0000 |
| Subject: | Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132856@lists.php.net to get a copy of this message | ||
Hello Rowan Tommins [IMSoP],
(Mirco Babin)
>OWASP states, see
>https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pre-hashing-passwords-with-bcryptdxJA›
>»ˆ'wþËQ
(Rowan Tommins [IMSoP])
>I looked up the attack discussed there, "password shucking" or
>"hash shucking", and as I understand it, it requires
>*the same inner hash* to be used somewhere else, that the attacker
>can match *to that user*.
(Mirco Babin) I did not write the article in question. I think these
questions would be better addressed to OWASP.
Kind regards,
Mirco Babin