3 ms·
bcrypt is actually a cipher, like standard blowfish but with a much more expensive key expansion function. When you call the bcrypt "hash function", what it is
by finnw 14y ago
bcrypt is actually a cipher, like standard blowfish but with a much more expensive key expansion function.
When you call the bcrypt "hash function", what it is really doing is performing this key expansion then using the resulting key to encrypt a constant string.
GP is right - you can use bcrypt as a regular cipher, and the extended key schedule will make brute-forcing harder.
It is inefficient and unnecessary though - a 384-bit key will not be attacked by brute force anyway, and blowfish's small block size of 64 bits can be problematic (you need to change the key quite frequently to prevent active attacks.)