5 ms·
A year after you leave the job, your team is told to build a new auth backend against the database, using a different bcrypt implementation. They just know to u
by skosch 6y ago
A year after you leave the job, your team is told to build a new auth backend against the database, using a different bcrypt implementation. They just know to use bcrypt, but not about your truncation hack. The deployment is a success.
Two weeks later, an angry user (the only one with a 100-digit password) complains that they can't log in anymore. The guy is the company's best-paying customer; the boss is furious. The whole team goes on a wild goose chase for two days and nights just to find out what happened, as clearly there's nothing wrong with their code.
A few years later, a former colleague shares the episode on HN. As you read the comments, it dawns on you that the idiot antagonist of the story is you. In this moment, you are enlightened.
- deleted 6y ago[deleted]
- fwip 6y agoThe point of the upstream post was that bcrypt implementations often already truncate your passwords to 72 characters. If you switch to a different bcrypt implementation that does/does not truncate at 72 characters, the server-side truncation keeps all those 73 character passwords working. If the server-side truncation were not in place, you'd get angry users.