On Thu, Oct 1, 2026, 8:01 AM Jordi Kroon <[email protected]> wrote:
> On 01/10/2026 12:11 am, Derick Rethans wrote: > > On 30 September 2026 22:26:21 BST, "Tim Düsterhus" <[email protected]> > wrote: > > > If a user of a site has a silly long password now, they can still login. > If this changes to an Exception, then they no longer can, without > intervention from a site owner, for whom there is now BC break in the > language throwing random new exceptions *based on user input*. > > I agree with Derick's concerns. This change could affect users who chose > long passwords because they believed they would be more secure. I don't > believe those users should be \'affected. > Please folks, read the RFC before parroting this line. The RFC only proposes changing password_hash(), NOT password_verify(). If a hash already exists from a truncated password, it will continue to validate. The only time this would raise the exception or error is when hashing, which will typically be done once, when a user registers, or chooses to change their password. Having an error condition here forces the application developer to address the truncation issue when storing new hashes only, and won't invalidate existing user hashes and login attempts. -- Matthew Weier O'Phinney [email protected] https://mwop.net/ he/him
