3 ms·
There is a discussion about that on the security stackexchange (https://security.stackexchange.com/questions/133239/what-is-the-specific-reason-to-prefer-bcrypt
by n0rdy 2y ago
There is a discussion about that on the security stackexchange (https://security.stackexchange.com/questions/133239/what-is-the-specific-reason-to-prefer-bcrypt-or-pbkdf2-over-sha256-crypt-in-pass https://security.stackexchange.com/questions/133239/what-is-...).
The TLDR:
> SHA-2 family of hashes was designed to be fast. BCrypt was designed to be slow.
Slow == harder to brute-force == more secure.
- progmetaldev 2y agoYes, and you can increase the work factor to make it slower to generate, specifically to fight against brute-force.