التجزئة/التشفير
Bcrypt Hash + Verify
تجزئة كلمات المرور باستخدام bcrypt (بملح عشوائي وتكلفة قابلة للتعديل) والتحقق من كلمة مرور مقابل هاش bcrypt موجود.
Bcrypt is a deliberately slow password-hashing algorithm: unlike MD5 or SHA-256, it intentionally requires heavy computation so that brute-forcing passwords stays impractical even if a database of hashes leaks.
How to use it
- Hash: enter a password and set a cost factor — a higher number means slower, more secure hashing.
- Every hash call generates a fresh random salt, so the same password produces a different hash each time — that's expected and normal.
- Verify: paste a password and an existing bcrypt hash to check whether they match, without hashing manually yourself.
Common uses
- Manually checking that a backend hashes passwords correctly before storing them.
- Generating a test bcrypt hash for seed data or fixtures during development.
- Debugging a failed login by comparing an entered password against the stored hash.
Things to keep in mind
Pick a cost factor that keeps hashing around 100-300ms on your target server — a balance between security and login-time load.
Bcrypt truncates passwords longer than 72 bytes — characters beyond that limit are ignored by the algorithm.
مقالة عن هذه الأداة: Bcrypt: لماذا تُجزَّأ كلمات المرور ببطء لا بسرعة
الأسئلة الشائعة
هل أحتاج إلى إنشاء ملح (salt) بشكل منفصل قبل استخدام bcrypt؟
لا، خوارزمية bcrypt تولّد ملحًا عشوائيًا تلقائيًا وتدمجه ضمن الهاش الناتج، فلا حاجة لإدارته أو تخزينه بشكل منفصل.
ماذا يحدث إذا كانت كلمة المرور أطول من 72 بايت؟
تقتصر خوارزمية bcrypt على أول 72 بايت من كلمة المرور فقط، وأي أحرف بعد هذا الحد تُقتطع بصمت دون أي تنبيه.
لماذا تستغرق عملية التجزئة وقتًا طويلًا عند زيادة قيمة التكلفة؟
رفع عامل التكلفة يضاعف زمن الحساب أسّيًا بشكل متعمد، فكلما زادت التكلفة زادت مقاومة الهاش لهجمات التخمين الآلي (brute force)، مع تباطؤ ملحوظ حسب قدرة الجهاز.
هل يوجد حد لطول كلمة المرور في bcrypt؟
نعم، تعالج خوارزمية bcrypt أول 72 بايت فقط من كلمة المرور — وأي شيء أطول يُتجاهل بصمت دون تنبيه. عمليًا نادرًا ما يشكّل هذا مشكلة، لكن يجدر تذكّر ذلك عند التعامل مع كلمات مرور طويلة جدًا أو أحرف غير ASCII قد يشغل الحرف الواحد منها عدة بايتات.
لماذا لا تزال bcrypt مُوصى بها رغم وجود Argon2؟
أثبتت bcrypt جدارتها عمليًا على مدى عقود، وهي مدعومة على نطاق واسع في جميع اللغات والأطر، وتظل خيارًا موثوقًا تمامًا. يُوصى بـ Argon2 كخيار أولوية للأنظمة الجديدة بفضل مقاومته لهجمات GPU/ASIC، لكن bcrypt لا تُعدّ غير آمنة — فقط أقل مقاومة للأجهزة المتخصصة.