Why Password Hashing Matters
When users create passwords, you should never store the raw password in your database. If your database is ever breached, attackers will have every user's password in plain text. Instead, store a one-way hash of the password — a mathematical fingerprint that cannot be reversed.
Why MD5 and SHA256 Are Wrong for Passwords
MD5, SHA256 and SHA512 are cryptographic hash functions designed for speed. A modern GPU can compute billions of SHA256 hashes per second. This makes them terrible for passwords — an attacker can try an entire dictionary of common passwords in milliseconds.
Why Bcrypt Is Different
Bcrypt is intentionally slow. It was designed specifically for password hashing with three key properties:
- Adaptive cost factor — you control how slow it is, so it can be made slower as hardware improves
- Automatic salting — bcrypt generates a random salt for each hash, so identical passwords produce different hashes
- Purpose-built — designed specifically for passwords, not general-purpose hashing
Understanding the Cost Factor
The cost factor (also called work factor) is a number that determines how many iterations bcrypt performs. At cost 10, bcrypt performs 2¹⁰ = 1,024 iterations and takes about 100ms. At cost 12, it performs 4,096 iterations and takes about 400ms. The OWASP recommendation is a minimum cost factor of 10.
The 72-Byte Limit Nobody Warns You About
Bcrypt silently truncates any input longer than 72 bytes — characters beyond that limit are simply ignored during hashing, which means two different passwords sharing the same first 72 bytes would hash identically. This rarely matters for typical passwords, but it's a genuine gotcha for anyone allowing very long passphrases or accepting Unicode input (where multi-byte characters eat into that 72-byte budget faster than their character count suggests), and it's a common source of confusing "why did this password verify against a different string" bugs.
Why Argon2 Is Now Often Recommended Instead
Argon2, the winner of the 2015 Password Hashing Competition, is now OWASP's top recommendation ahead of bcrypt for new systems, because it can be tuned for both CPU and memory cost — making it more resistant to GPU and ASIC-based cracking attempts, which are optimized for exactly the kind of computation bcrypt relies on. Bcrypt remains a solid, battle-tested choice for existing systems, but Argon2id is generally the better default for anything built from scratch today.
Generate and Verify Bcrypt Hashes
Our Bcrypt Hash Generator generates real bcrypt hashes server-side using PHP's password_hash() function and verifies passwords against existing hashes.


