2026-09-23 19:50 UTC
bcrypt truncates inputs after 72 bytes.
An attacker can set their own password to a 71-byte string, extract the hash, and recover the first byte of the pepper. (they don't even need the SQLi, attempting to log in with `$71_byte_string . $pepper_guess` is just as good an oracle)
They can then recover the entire pepper byte-by-byte by repeating this with shorter and shorter passwords.
With the pepper leaked, they can use the SQLi to leak all hashes and begin cracking all passwords.
Replies (1)
-
@embers@chaos.social 2026-09-23 19:57
This is, btw, the exact construction used in the first result that pops up when you search "how to apply pepper to hash" (https://security.stackexchange.com/questions/21263/how-to-apply-a-pepper-correctly-to-bcrypt) Several of you had the good intuition that concatenation is *fishy*. The folks on SE did not, merely remarking that it is "a tad less elegant, mathematically speaking."