My Learning About Password Hashing After Moving Beyond Bcrypt

For a long time, I thought I had password hashing figured out.

Like many Java developers, I relied on bcrypt, mostly because it’s the default choice in Spring Security. It was easy to use, widely recommended, and treated in tutorials as “the secure option.” I plugged it in, shipped features, and moved on.

This article has been indexed from DZone Security Zone

Read the original article: