bcrypt
ExplainedConcept
Password-hashing algorithm that is deliberately slow to make brute-force attacks expensive.
bcrypt, explained
Written by EduVerseWhat it is
bcrypt is a hashing algorithm made specifically for passwords. It turns a password into a string that can’t be reversed, mixes in a random salt so identical passwords get different hashes, and has a cost factor that controls how much work each hash takes.
Why teams use it
If your database ever leaks, attackers will try enormous numbers of guesses against the stored hashes. Fast hashes like MD5 or SHA-256 make that cheap; bcrypt is slow on purpose, so every guess costs real time. You can raise the cost factor as hardware gets faster. Alternatives such as Argon2 and scrypt follow the same idea.
An example from work
You open the users table and the password column holds values starting with $2b$12$, followed by a long run of characters. The $2b$ marks bcrypt, 12 is the cost factor, and the salt is stored inside that same value. At login your code doesn’t decrypt anything: it hashes the typed password the same way and compares the results.
Our own explanation, not a quote from the book.
Where it fits
Storing passwords safely in databases
Coverage in the book
Explained and compared with alternatives, so you know where and why it’s used.