I appreciate the debate on this topic, and I am in support of the RFC.
It sounds to me like the API has been lost in the debate though.
We all agree Bcrypt is working as intended.
What we are seeing in password_hash() is an unhelpful API. The function
accepts an input of arbitrary length, but the manual contradicts the
arbitrary length usage with a not-entirely-accurate "Caution" block
about the length of the input. It specifically says PASSWORD_BCRYPT,
and misses the identical concerns with PASSWORD_DEFAULT or null.
What the manual doesn't illustrate is a real case where
password_verify() doesn't verify the password.
$hash = password_hash('one two three four five six seven eight nine ten
eleven twelve thirteen epic secure password', PASSWORD_DEFAULT);
$result = password_verify('one two three four five six seven eight nine
ten eleven twelve thirteen ', $hash);
var_dump($result);
A developer might ask why the application is doing this, but the RFC
asks why is PHP doing this? Is the function named password_verify going
to verify the password or not?
_____________
Robert Chapin