Skip to main content

2026-03-06

8 min

By Formatho Editorial

How Bcrypt Hashing Keeps Your User Passwords Safe

SecurityPasswordsBcrypt
Digital padlock representing password security and encryption

Why passwords need slow hashing

Fast hashes like SHA-256 exist to verify data quickly — which is exactly wrong for passwords. A GPU can try billions of SHA-256 guesses per second, so when a database leaks, 8-character passwords fall in hours. bcrypt is deliberately slow: its cost factor (2cost rounds) lets you tune each guess to take tens of milliseconds, turning a breach from a weekend into centuries — and its built-in salt kills rainbow tables and makes identical passwords hash differently.

Anatomy of a bcrypt hash

$2b$12$R9h/cIPz0gi.URNNX3kh2OPST9/PgBkqquzi.Ss7KIUgO2t0jWMUW
 │   │  └────────────┬─────────────┘└──────────┬───────────┘
 │   │        22-char salt              31-char hash
 └── algorithm  cost factor (2^12 rounds)

Everything needed to verify is inside the string: the algorithm version (2a/2b/2y), the cost, the salt, and the digest. You store the whole thing; verification re-runs the same cost and compares.

Using it correctly

  • Cost factor: target ~100–250 ms per hash on your production hardware — commonly 11–13 today. Raise it as CPUs improve; the cost travels with the hash, so old hashes verify forever while new ones get stronger.
  • Never pre-hash with SHA-256 to "normalize" length: bcrypt truncates input at 72 bytes, and pre-hashing has caused real vulnerabilities (pass-the-hash via the SHA digest). For long passphrases, bcrypt's 72-byte limit is acceptable in practice; if not, use Argon2id instead.
  • Always use a vetted library (bcryptjs in Node, bcrypt in Python) — the comparison must be constant-time, which libraries provide and hand-rolled code doesn't.
  • Salt is automatic — don't add your own; generating it per-password is the library's job.

bcrypt vs the alternatives

Argon2id (the Password Hashing Competition winner) adds memory-hardness, resisting GPUs even better, and is the first choice for new systems; scrypt is the middle ground; bcrypt remains a perfectly sound, battle-tested default. All three belong to the "slow, salted" family — the only family acceptable for password storage. MD5, SHA-1, and plain SHA-256 do not.

Generate bcrypt hashes with adjustable cost and verify round-trips locally in the bcrypt tool.

Formatho Editorial — written and maintained by the team behind formatho.com, a library of free, privacy-first developer tools that run entirely in your browser. Every guide is tested against the tools it describes. Corrections and suggestions: github.com/formatho.