2 ms·
56, actually. It's a major shortcoming of bcrypt, and an argument in favour of algorithms like scrypt and PBKDF2. If you're committed to bcrypt, you could make
by jdpage 12y ago
56, actually. It's a major shortcoming of bcrypt, and an argument in favour of algorithms like scrypt and PBKDF2.
If you're committed to bcrypt, you could make an argument in favour of digesting the password with something like SHA384 first. That reduces entropy, but (a) it's strictly better than straight SHA, which is what a concerning number of people use already, and (b) it means that you're not messing up the user's pattern/mnemonic if they've got one going.