On Thu, Oct 1, 2026, at 10:21, Tim Düsterhus wrote:
> To provide a constructive suggestion: Borrowing passlib’s 
> `bcrypt-sha256` 
> algorithm (including the output format) might be a valid option for a 
> well-defined pre-hashing solution.

Yes, having another password hashing algorithm that does not truncate (like 
bcrypt) and is included by default (unlike argon2) would be great.

However, I was under the impression that this was problematic, seeing the lack 
of progress on yescrypt. Perhaps bcrypt-sha256 is different since we already 
have both fundamental functions built in?

yescrypt PR: https://github.com/php/php-src/pull/16452

Regards,

Sjoerd

Reply via email to