Which password-hashing algorithm was designed by Niels Provos and David Mazières in 1999?

The story behind the answer

The password-hashing algorithm designed by Niels Provos and David Mazières in 1999 was bcrypt.

bcrypt was created for OpenBSD and is based on the Blowfish symmetric-key cipher. Unlike ordinary fast hashes, it was designed to make password guessing expensive by using a configurable cost factor. As computers become faster, systems can increase that factor to require more computation for each password attempt.

bcrypt’s design also uses a deliberately small memory requirement and a 128-bit salt. Salting ensures that identical passwords do not produce identical stored hash values, while the work factor slows large-scale brute-force attacks and makes precomputed rainbow tables less useful.

bcrypt is often confused with encryption because both involve cryptography, but bcrypt is a one-way password-hashing function, not a method for recovering plaintext passwords. Modern password-storage guidance also discusses memory-hard alternatives such as scrypt and Argon2, especially for new systems.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: