हैश/क्रिप्टो
Bcrypt Hash + Verify
bcrypt से पासवर्ड हैश करें (रैंडम सॉल्ट और अनुकूलनीय कॉस्ट के साथ) और किसी मौजूदा bcrypt हैश के विरुद्ध पासवर्ड वेरिफाई करें।
Bcrypt is a deliberately slow password-hashing algorithm: unlike MD5 or SHA-256, it intentionally requires heavy computation so that brute-forcing passwords stays impractical even if a database of hashes leaks.
How to use it
- Hash: enter a password and set a cost factor — a higher number means slower, more secure hashing.
- Every hash call generates a fresh random salt, so the same password produces a different hash each time — that's expected and normal.
- Verify: paste a password and an existing bcrypt hash to check whether they match, without hashing manually yourself.
Common uses
- Manually checking that a backend hashes passwords correctly before storing them.
- Generating a test bcrypt hash for seed data or fixtures during development.
- Debugging a failed login by comparing an entered password against the stored hash.
Things to keep in mind
Pick a cost factor that keeps hashing around 100-300ms on your target server — a balance between security and login-time load.
Bcrypt truncates passwords longer than 72 bytes — characters beyond that limit are ignored by the algorithm.
इस टूल के बारे में लेख: Bcrypt: पासवर्ड धीरे क्यों हैश किए जाते हैं, तेज़ नहीं
अक्सर पूछे जाने वाले प्रश्न
bcrypt में "cost" (जटिलता) फैक्टर क्यों होता है?
कॉस्ट फैक्टर यह नियंत्रित करता है कि हैशिंग आंतरिक रूप से कितनी बार दोहराई जाए, इसलिए इसके बढ़ने पर हैशिंग तेज़ी से धीमी होती जाती है। इससे आप इसे जानबूझकर इतना धीमा रख सकते हैं कि हार्डवेयर तेज़ होने पर भी ब्रूट-फोर्स हमलों का प्रतिरोध बना रहे।
bcrypt का हैश हमेशा एक जैसी लंबाई का क्यों होता है, चाहे पासवर्ड कोई भी हो?
Bcrypt एक निश्चित-लंबाई का हैश (आमतौर पर 60 अक्षर) देता है जिसमें एल्गोरिद्म वर्शन, कॉस्ट फैक्टर, सॉल्ट और हैश एक साथ एन्कोड होते हैं — लंबाई मूल पासवर्ड की लंबाई पर निर्भर नहीं करती।
क्या bcrypt को अलग सॉल्ट फ़ील्ड की ज़रूरत होती है?
नहीं। सॉल्ट स्वतः जनरेट होता है और सीधे आउटपुट स्ट्रिंग में एम्बेड हो जाता है, इसलिए इसे अलग से स्टोर या मैनेज करने की ज़रूरत नहीं — जब भी आप हैश के विरुद्ध पासवर्ड सत्यापित करते हैं, यह शामिल रहता है।
क्या bcrypt में पासवर्ड की लंबाई की कोई सीमा है?
हाँ, bcrypt पासवर्ड के केवल पहले 72 बाइट्स प्रोसेस करता है — इससे ज़्यादा कुछ भी बिना किसी चेतावनी के छोड़ दिया जाता है। व्यवहार में यह शायद ही कभी समस्या बनता है, लेकिन बहुत लंबे पासवर्ड या नॉन-ASCII कैरेक्टर के साथ काम करते समय इसे याद रखना ज़रूरी है, जहां एक कैरेक्टर कई बाइट्स ले सकता है।
अगर Argon2 मौजूद है, तो bcrypt की सलाह अब भी क्यों दी जाती है?
Bcrypt दशकों से व्यवहार में परखा जा चुका है, हर भाषा और फ़्रेमवर्क में व्यापक रूप से समर्थित है, और पूरी तरह भरोसेमंद विकल्प बना हुआ है। GPU/ASIC अटैक से बेहतर बचाव के कारण नए सिस्टम के लिए Argon2 को प्राथमिकता दी जाती है, लेकिन bcrypt को असुरक्षित नहीं माना जाता — बस स्पेशलाइज़्ड हार्डवेयर के प्रति कम प्रतिरोधी माना जाता है।