-----Original Message-----
From: Tim Düsterhus <[email protected]> 
Sent: Wednesday, September 30, 2026 6:08 PM
To: Rowan Tommins [IMSoP] <[email protected]>
Cc: [email protected]
Subject: Re: [PHP-DEV] [RFC] Throw error for passwords longer than 72 bytes in 
password_hash() with bcrypt


>> It seems to me that refusing those inputs and alerting the developer 
>> to the limitation leaves the *overall system* more secure.

> My expectation is that developers who are “alerted” to the limitation will 
> just go with whatever solution makes the error message go away the quickest 
> instead of trying to understand the impact

=====

If that's the case, then the "throw" proposal is an obvious win. Developers who 
would do as you feel have an easy remedy. Those who are competent are warned of 
a significant security issue, that they can properly analyze and resolve.

-Jeff

Reply via email to