Why Do Modern Systems Use Bcrypt for Passwords?
Standard hashes like MD5 or SHA-256 are designed to be fast, enabling attackers to test billions of guesses per second on modern GPUs. Bcrypt is deliberately slow and includes an adaptive cost factor (rounds). Each increment doubles computation time, neutralizing rainbow table and brute-force attacks.
Bcrypt 60-Character Hash Structure
形如 $2a$10$N9qo8uLOickgx2ZMRZoMyeIjZAgcfl7p92ldGxad68LJZdL17lhWy 的标准 Bcrypt 串可拆解为四段:
$2a$:Bcrypt algorithm specification identifier.10$:Cost factor (2¹⁰ = 1,024 key expansion rounds).N9qo8uLOickgx2ZMRZoMye:The first 22 characters encode the 128-bit random salt.IjZAgcfl7p92ldGxad68LJZdL17lhWy:The remaining 31 characters encode the 184-bit ciphertext checksum.