PHP RFC would reject oversized bcrypt passwords
Sjoerd Langkemper has proposed the PHP RFC bcrypt_max_password_length.
It would make password_hash() throw ValueError when bcrypt receives input longer than 72 bytes. PHP currently truncates longer input silently, hashing only the first 72 bytes. The change targets severe security vulnerabilities, especially in applications that hash data beyond a user’s password.
Sjoerd Langkemper has drafted the PHP RFC bcrypt_max_password_length. It proposes that password_hash() throw ValueError when bcrypt receives a password longer than 72 bytes.
PHP currently truncates longer input without warning and hashes only the first 72 bytes. The proposal aims to prevent severe security vulnerabilities caused by this behavior. It would primarily affect applications that pass data other than the user’s password to password_hash().
Readers’ Forum
No contributions yet — open the debate.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.