9 ms·
bcrypt is a key derivation function based on the Blowfish cipher. The iteration count can be increased to make it slower, so it remains resistant to brute-force
by chill1 12y ago
bcrypt is a key derivation function based on the Blowfish cipher. The iteration count can be increased to make it slower, so it remains resistant to brute-force search attacks even with increasing computation power. The hash string includes the cost parameter, a salt, and the hash value. [1] This allows you to change the number of iterations and length of salt at any time, and all previously generated hashes will still be valid. It does not, however, adjust itself automatically depending upon the computational power of the computer on which it is running.
[1] https://en.wikipedia.org/wiki/Bcrypt https://en.wikipedia.org/wiki/Bcrypt