4 ms·
The string output from the bcrypt function always contains a 22-character salt embedded within it, so these are salted. This is placed after an initial algorith
by estreeper 6y ago
The string output from the bcrypt function always contains a 22-character salt embedded within it, so these are salted. This is placed after an initial algorithm identifier (i.e. $2a$) and an adjustable cost used to generate the output string (i.e. 10$). There's an overview of the structure of the output string here if you're interested: https://en.wikipedia.org/wiki/Bcrypt https://en.wikipedia.org/wiki/Bcrypt
However, if your password is "password" or another very common password, then someone can just try those with the embedded salt and still find out that was your password.
- ALittleLight 6y agoVery interesting - thanks. You'd still have to crack each password individually though, right? i.e. for row 1 I would need to try X passwords from my password dictionary, and for each of the attempts bcrypt the guess with the given salt and check to see if worked, and then repeat that for each row individually, rather than checking every row simultaneously.
- caf 6y agoRight, you have to check each row separately.