3 ms·
They're two completely different things. AES is an encryption algorithm. bcrypt is a special-purpose hash algorithm. If you're confused, I'd highly recommend P
by codahale 17y ago
They're two completely different things. AES is an encryption algorithm. bcrypt is a special-purpose hash algorithm.
If you're confused, I'd highly recommend Practical Cryptography by Niels Furguson and Bruce Schneier: http://www.schneier.com/book-practical.html http://www.schneier.com/book-practical.html
It will give you much better advice than the internet will.
- deleted 17y ago[deleted]
- revelate 17y agoHTTP Digest support pretty much requires you to hash passwords using MD5(salt:password), if there’s a way to support HTTP Digest while storing bcrypt hashed passwords I’d love to know. Why do we care about HTTP Digest? It provides a standard technique to avoid sending clear passwords from client to server. This is particularly handy when the client server communication isn’t encrypted (a poor man’s SSL if you will), but sounds like a good idea in general. In principle you could create a variant of HTTP Digest using bcrypt instead of MD5 however you’d break browser and rss reader compatibility and AFAIK there are currently no javascript bcrypt implementations. Hence I’m guessing that web apps storing bcrypt hashed passwords are forced to send clear-ish passwords from client to server and therefore must rely on the presence of an ssl/https connection. Obviously ssl should be used whenever possible, but I wonder to what extent sending clear passwords doesn’t create other forms of vulnerability?