bcrypt
Password hashing function. Niels Provos + David Mazières, 1999. Adaptive via "work factor" (cost) — increase as CPUs get faster. Salt embedded in hash output (self-describing). Default choice 1999-2020.
Cost 12 (4096 iterations) is current minimum for server-side hashing 2025. One hash costs ~250ms on modern CPU. Output format: $2b$12$saltsaltsalt22charsHashHashHash31. Competitors: Argon2 (PHC winner 2015, memory-hard, recommended 2025), scrypt (memory-hard, less used). Modern best practice: Argon2id for new systems, bcrypt still OK if legacy. Length limit: 72 bytes input (silent truncation) — pad or use SHA-256 prefix.