Cryptography & Security
Password hashing with bcrypt, session secrets, and safe patterns
bcrypt Password Hashing
Use ASPPY.crypto.Hash(password, rounds) to hash passwords.
| Password | ***** |
|---|---|
| bcrypt hash | $2b$10$nVD5Ivj/UQOS4KdRw4dQne.SBrHXBG1nEr7pXsfrp7iPSlz6Ol/0y |
| Length | 60 chars |
Verify Password
Use ASPPY.crypto.Verify(password, hash) to check.
Stored hash: $2b$10$v7xBSMINLnk1zdzT6P6NB.KlxV4JBtmIt...
Try "testpassword" (correct) or any other value.
Secure Session Secret
Derive a per-session secret using bcrypt hash as key material.
Your session secret: $2b$10$E3auTMZxUHtJfOTZeAPjQ.VTjxVDp8EGs...
Generated once per session using bcrypt with a random seed.
Safe Password Storage Pattern
bcrypt already includes a random salt — just hash and store the result.
| Password | *********** |
|---|---|
| Hash #1 | $2b$10$9Tddy3sYvwOG1LKQSsC69.39Ej8RLve.Xpu589mNNGmMPmS7MG9z2 |
| Hash #2 | $2b$10$/7f/hap44twwS5/q2l9uZ.LdfXng1pGXjMeVsavXiUxrvbPZ/YjRK |
| Same password? |
Note: each hash is different because bcrypt generates a new random salt every time.