Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
| From: | Rowan Tommins [IMSoP] | Date: | Fri, 09 Oct 2026 16:24:47 +0000 |
| Subject: | Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132857@lists.php.net to get a copy of this message | ||
On 9 October 2026 15:03:11 BST, Mirco Babin <mirco.babin@gmail.com> wrote:
> I did not write the article in question. I think these
>questions would be better addressed to OWASP.
I didn't ask you any questions, nor do I have any questions I want to ask the OWASP authors.
You stated that the algorithm Sjoerd proposed including "goes against OWASP
recommendations". I looked at the page you linked to, did some follow-up research of terms it
mentioned, and I disagree with your conclusion.
My conclusion is that the page you linked discusses a possible vulnerability in similar algorithms,
and suggests an algorithm that doesn't have that vulnerability. The algorithm proposed in this
thread is not identical to that OWASP suggestion, but it has a different feature which addresses the
same vulnerability.
As such, I think the algorithm is worth considering further.
Regards,
Rowan Tommins
[IMSoP]