3 ms·
Cryptographic question: Why don't you just SHA-2-hash the Bcrypt hashes? hash = sha2(bcrypt(plaintext))
by cstuder 6y ago
Cryptographic question: Why don't you just SHA-2-hash the Bcrypt hashes?
hash = sha2(bcrypt(plaintext))
- ccouzens 6y agobcrypt(plaintext) != bcrypt(plaintext) The output of the function includes a random salt. The verify function looks like verify(plaintext, hash) This is why the bcrypt cyphertext needs to be stored
- onei 6y agoYou could use hash the password with sha2 and then with bcrypt, but not the other way around. Hashing with sha2 will give you the same result every time. That's why it's appropriate to use as a checksumming algorithm - the results are repeatable. Bcrypt on the other hand does not generate the same result every time by design due to it using a randomly generated salt. However, if you did hash with sha2 the first time, you may end up regretting that decision if sha2 collisions end up being possible and/or practical.
- daneel_w 6y agoThat would not be possible, but one could use bcrypt to generate a salt to use with SHA2 as the last step.