On Tue, Sep 29, 2026, at 15:51, Tim Düsterhus wrote:
> The API is safe if you pass a “password” to it (as the name indicates). 
> The issues described in the RFC were caused by folks passing something 
> that is not a password.

Exactly, and my proposal aims to throw a ValueError in those cases, indicating 
that it is a programming error to pass anything other than password. The 
tradeoff is that actual passwords longer than 72 bytes are no longer supported. 
I think that is acceptable. I have gathered data showing that such passwords 
are exceedingly rare. Also, if users genuinely need longer passwords, it is 
also not defensible to silently truncate the password.

> The login will start to fail when the password is being rehashed 
> (password_needs_rehash()) due to a change in the algorithm parameters

That is a good point, I had not considered that. Thanks.

Regards,

Sjoerd

Reply via email to