PHP's default password hash only reads the first 72 bytes of your password. Last week's plan to refuse longer ones split the list. This week, a fix that breaks nothing arrived, borrowed from a Python library.
Explore
Pick a password longer than 72 bytes and PHP's default hash keeps only the first 72, so a shortened password still logs you in. An RFC wants PHP to refuse instead, and the list can't agree it's worth the break.
