On Tue, Sep 29, 2026, at 15:51, Tim Düsterhus wrote: > The API is safe if you pass a “password” to it (as the name indicates). > The issues described in the RFC were caused by folks passing something > that is not a password.
Exactly, and my proposal aims to throw a ValueError in those cases, indicating that it is a programming error to pass anything other than password. The tradeoff is that actual passwords longer than 72 bytes are no longer supported. I think that is acceptable. I have gathered data showing that such passwords are exceedingly rare. Also, if users genuinely need longer passwords, it is also not defensible to silently truncate the password. > The login will start to fail when the password is being rehashed > (password_needs_rehash()) due to a change in the algorithm parameters That is a good point, I had not considered that. Thanks. Regards, Sjoerd
