Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash

From: Date: Fri, 09 Oct 2026 16:24:47 +0000
Subject: Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-132857@lists.php.net to get a copy of this message
On 9 October 2026 15:03:11 BST, Mirco Babin <mirco.babin@gmail.com> wrote: > I did not write the article in question. I think these >questions would be better addressed to OWASP. I didn't ask you any questions, nor do I have any questions I want to ask the OWASP authors. You stated that the algorithm Sjoerd proposed including "goes against OWASP recommendations". I looked at the page you linked to, did some follow-up research of terms it mentioned, and I disagree with your conclusion. My conclusion is that the page you linked discusses a possible vulnerability in similar algorithms, and suggests an algorithm that doesn't have that vulnerability. The algorithm proposed in this thread is not identical to that OWASP suggestion, but it has a different feature which addresses the same vulnerability. As such, I think the algorithm is worth considering further. Regards, Rowan Tommins [IMSoP]

« previous php.internals (#132857) next »