-----Original Message----- >> It will still match. A hash of 72-byte long password and a hash of >> 73-byte long password where the first 72 bytes are the same will match. >> https://urldefense.proofpoint.com/v2/url?u=https-3A__3v4l.org_o7dJq-23v >> 8.5.11&d=DwIFaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=i0NKIgJ >> vrKCThBAHo8lLTC9DcIc_YQfpu9rIABLCJDI&m=BfKD0IS6H873YHy61CdrQdPZPt8HtJQQ >> ssJtrmymWnZI8VB-PIfGO_Be4ovErFMc&s=ctggKP-MeLZgXCyZvKx30hgf4i3E-uSaRhl9 >> _u92xHY&e=
> Yes, and that is a false positive - the user provides the wrong password, and > the system lets them in. > Rowan Tommins > [IMSoP] ===== For what it's worth, I stumbled across this issue recently in the older part of our PHP codebase. After coming up with a solution, we forced PW resets for the impacted users. And, to Rowan's point, if this had thrown an exception (or even a warning, tbh) during any PHP version upgrade we would've caught it many years ago. Looking through the lens of software security in 2026, I cannot think of any situation where this function should silently accept more bytes than it can hash. Thank you all for your work on the PHP project. -Jeff (non-voter, trying to influence the vote)
