4 ms·
But why not bcrypt the password, but sha the cache key on top?
by coolgoose 2y ago
But why not bcrypt the password, but sha the cache key on top?
- stavros 2y agoI guess because they didn't anticipate this flaw.
- masklinn 2y agoAlso prehashing opens you up to an other bcrypt flaw you need to be aware of: it stops at the first NUL byte, so you need to use some sort of binary-to-text encoding on top of the hash to ensure you don't have any of those in the data you ultimately hand off to bcrypt.
- Dylan16807 2y agoIt's astounding how bad the default API for Bcrypt is.
- coolgoose 2y agoThank you