Study. uk . com
  1. Home
  2. All questions
  3. Question 536

CompTIA Security+ study material · question 536 of 611

An application uses bcrypt and accepts passwords of any length. What must it also enforce?

  1. A unique pepper per user
  2. A maximum length of 72 bytes
  3. A minimum work factor of 6
  4. A salt of at least 64 bits
Show the answer

Answer: B. A maximum length of 72 bytes

Most bcrypt implementations silently truncate beyond 72 bytes, so the extra characters give no additional strength.

Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › Input Limits of bcrypt

Challenge yourself on this topic → Study as cards