2026-09-23 20:21 UTC
@embers@chaos.social why in the fuck would bcrypt truncate inputs
Replies (1)
-
@embers@chaos.social 2026-09-23 20:28
@green@mk.absturztau.be ... because.. fine.. ok.. bcrypt hashes the password by using it as a key to encrypt the constant string "OrpheanBeholderScryDoubt". The key procedure accepts a 56 byte key. Which is why the bcrypt spec only accepts up to 55 bytes (+1 null terminator) When OpenBSD did the first implementation though, they realized you neither need terminators on full-length strings, and that the key can actually be influenced by up to 72 bytes if you change the cipher slightly. All in all: AHHHHHHHHHH