Post
Len Woodward
projektgopher.com
did:plc:ix4islhkrpq7bjujwgsm234t
Pick a password longer than 72 bytes and PHP's default hash keeps only the first 72, so a shortened password still logs you in. An RFC wants PHP to refuse instead, and the list can't agree it's worth the break.
https://youtu.be/3Hp0E0SbusM
#PHP #PHPInternals #PHP87
2026-10-02T00:56:32.057Z