Hello,

I have drafted a new RFC: https://wiki.php.net/rfc/bcrypt_max_password_length

The proposal is to throw a ValueError when a password longer than 72 characters 
is passed to password_hash and bcrypt is used. The current behavior is that the 
password is silently truncated and only the first 72 characters are hashed.

The goal is to prevent severe security vulnerabilities that are the result of 
this silent truncation. This will primarily impact applications that pass 
something else than just the user's password to password_hash. Please let me 
know what you think!

Regards,

Sjoerd

Reply via email to