3 ms·
Hashing the access token with bcrypt isn't really a good idea. Bcrypt is designed to be slow, and hashing the submitted token on EVERY request would really aff
by LammyL 14y ago
Hashing the access token with bcrypt isn't really a good idea. Bcrypt is designed to be slow, and hashing the submitted token on EVERY request would really affect performance. Bcrypt is great for password hashing which only happens once per session. You are probably better off securing access tokens using a fast hash (sha) and compensating for security with a long and random access token.
- tedunangst 14y agoYes, sha2 is more than sufficient for protecting auth tokens. If it's not, the problem is your auth tokens are too simple.