I’ve an old legacy application using Spring Security (3.1.0) for the BCrypt implementation. The hashes have some format like
$2a$10$Cas1.FrwwQ3...WqS1i31gHrk12J9YK
For the implementation the encoder:
PasswordEncoder BCRYPT = new BCryptPasswordEncoder(BCRYP_ITERATIONS);
is used for creating hash (to be stored in database) and for matching.
My questions are:
If I simply change the
BCRYP_ITERATIONSfrom currently 10 to 18 would this break my login?
From how I understand BCrypt it would not – as for the matching it would simply use the iteration value that is stored inside the hash itself ($2a$10$). And for creating new hashes to be stored in database the new value is used.If I’m updating the library to recent implementation that uses new version (
$2b$) of BCryprt – would this break my login?
As it somehow changes the method I would say yes – is this true?