Drupal 12 will introduce Argon2id as its default password hashing algorithm, replacing bcrypt and aligning the platform with current security best practices recommended by OWASP and NIST. The change, outlined by Drupal founder Dries Buytaert, strengthens resistance against modern hardware-based attacks while maintaining backward compatibility. Existing passwords will be automatically rehashed upon user login, ensuring a seamless transition for site owners and users without requiring manual intervention.
...more