-----Original Message----- From: Tim Düsterhus <[email protected]> Sent: Wednesday, September 30, 2026 6:08 PM To: Rowan Tommins [IMSoP] <[email protected]> Cc: [email protected] Subject: Re: [PHP-DEV] [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
>> It seems to me that refusing those inputs and alerting the developer >> to the limitation leaves the *overall system* more secure. > My expectation is that developers who are “alerted” to the limitation will > just go with whatever solution makes the error message go away the quickest > instead of trying to understand the impact ===== If that's the case, then the "throw" proposal is an obvious win. Developers who would do as you feel have an easy remedy. Those who are competent are warned of a significant security issue, that they can properly analyze and resolve. -Jeff
