On Thu, Oct 1, 2026, at 10:21, Tim Düsterhus wrote: > To provide a constructive suggestion: Borrowing passlib’s > `bcrypt-sha256` > algorithm (including the output format) might be a valid option for a > well-defined pre-hashing solution.
Yes, having another password hashing algorithm that does not truncate (like bcrypt) and is included by default (unlike argon2) would be great. However, I was under the impression that this was problematic, seeing the lack of progress on yescrypt. Perhaps bcrypt-sha256 is different since we already have both fundamental functions built in? yescrypt PR: https://github.com/php/php-src/pull/16452 Regards, Sjoerd
