Höher = langsamer + sicherer. Cost 12 dauert auf einem typischen Laptop etwa 4ms; 10-12 ist der übliche Produktionsbereich.
Läuft zu 100 % in Ihrem Browser - Passwort und Hash verlassen Ihr Gerät nie.
I am storing user passwords for a web app with at most 10 000 users. Compare bcrypt (cost 12), scrypt, and Argon2id for this workload: resistance to GPU cracking, memory requirements, DoS risk on the login endpoint, and the parameters you would actually deploy. Give a concrete recommendation and the exact parameter values.
Was es tut
Bcrypt
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
& Verify hasht ein Passwort mit bcrypt - dem Algorithmus, eigens für das Speichern von Passwörtern gebaut - und prüft ein Passwort gegen einen bestehenden bcrypt-Hash. Beim Hashen wird ein frisches 16-Byte-Zufalls-SaltSaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
gezogen und der EksBlowfish-Key-Schedule2^cost-mal durchlaufen, sodass du exakt steuerst, wie teuer jeder Rateversuch ist. Die Verifikation rechnet den Digest mit dem eigenen SaltSaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
und Cost des Hashes nach und sagt dir, ob es passt. Akzeptiert werden$2a$, $2b$- und $2y$-Hashes - das Tool funktioniert also mit Hashes aus Node, Go, Python, PHP, Java, PostgreSQLs pgcrypto und jeder von OpenBSD abstammenden Implementation.
Alles läuft in deinem Browser, aus einer von Grund auf selbst geschriebenen Blowfish-Implementation (keine externe Krypto-Bibliothek). Das Passwort, das du tippst, und der
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
, den du einfügst, verlassen dein Gerät nie.So verwendest du es
- Wähle einen Modus mit dem
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
/ Verify-Toggle oben. HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
: tippe das Passwort (der Augen-Knopf zeigt es), ziehe den Cost-Faktor-Regler (4-16, default 12) - höher heißt langsamer und sicherer - und drücke dann Passwort hashen. Der$2b$-HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
erscheint mit Kopier-Knopf und einem Badge, das zeigt, wie lange es dauerte.- Verify: füge den bcrypt-
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
ein und tippe das Passwort zum Prüfen. Das Tool dekodiert den Hash live und zeigt Version, Cost undSaltSaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
. Drücke Passwort verifizieren für ein grünes Match ✓- oder rotes No match ✗-Badge. - Nutze Beispiel in beiden Modi, um Beispiel-Eingaben zu laden (das Verify-Beispiel ist ein echtes, passendes Paar).
Beispiele
Ein Passwort mit Cost 12 hashen
Passwort: correct horse battery staple → drücke Passwort hashen. Die Ausgabe sieht so aus:
$2b$12$9IZSN8TXXnSIx4aI0Cd2DetqQ/3FT9d6KJ9fl96SnULIK5x5q/moq
Jeder Lauf erzeugt einen anderen
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
- dasSaltSaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
ist jedes Mal frisch zufällig - und alle verifizieren gegen dasselbe Passwort.Einen HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Füge $2a$04$RPx7yiCLNb09VKAUBVNsnOVNzB1Zp/hE1qbDvGUs1aehNX5hE15su mit Passwort password ein → Match ✓. Die Badges dekodieren es als Version $2a$, Cost 4,
SaltSaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
RPx7yiCLNb09VKAUBVNsnO.
Das HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
$2b$12$ + 22 Zeichen
SaltSaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
+ 31 Zeichen Digest = 60 Zeichen insgesamt. Die12 ist der Cost: 2¹² = 4 096 EksBlowfish-Runden liefen, um den Key-Schedule zu bauen.
Gut zu wissen
- Warum bcrypt plain SHA-256 für Passwörter schlägt: SHA-256 ist schnell - genau das willst du nicht. Eine moderne GPU rechnet Milliarden SHA-256 pro Sekunde, aber nur Zehntausende bcrypt-Hashes, weil bcrypts Cost-Faktor 2^cost sequenzielle Key-Schedule-Runden erzwingt und sein
SaltSaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
Rainbow-Tables und die Wiederverwendung über Accounts verhindert. Aus demselben Grund schlägt bcrypt auch MD5 und SHA-1 klar - beide sind kollisionsgebrochen und viel zu billig zu berechnen. - Cost ist ein Stellrad, keine Konstante: wähle den langsamsten Cost, den deine Nutzer und deine Hardware ertragen - grob 250 ms bis 1 s pro
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
auf deinen Login-Servern. Heute heißt das Cost 10-12; erhöhe ihn alle paar Jahre, wenn die Hardware schneller wird. Die Verifikation zahlt denselben Cost wie das Hashen - ein absurd hoher Cost bremst also auch deine eigenen Logins und kann zum Denial-of-Service-Hebel am Login-Endpoint werden. - 72-Byte-Limit: bcrypt liest höchstens die ersten 72 Bytes des Passworts, und dieses Tool befolgt die Regel exakt. Der moderne Rat lautet, mit SHA-256 vorzuhashen, wenn du lange Passphrasen unterstützen musst - aber sorgfältig (
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
zuerst über die rohe Länge, sonst erbst du SHA-256s Null-Byte-Mehrdeutigkeiten). - Erfinde nie deinen eigenen Vergleich: verifiziere immer mit einem zeitkonstanten Vergleich, wie dieses Tool ihn nutzt - String-Gleichheit auf Hashes leakt Timing-Informationen.
- Alternativen, wenn du wählen kannst: Argon2id (memory-hard, Gewinner der Password
HashingHashingA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Competition) und scrypt sind stärker gegen GPU-/ASIC-Angreifer; bcrypt bleibt eine kampferprobte, überall unterstützte Baseline. - Verwandte Tools: Password Strength Analyser, Password Generator, HMAC Generator.