Securely generate Bcrypt hashes or verify passwords against existing hashes.
Bcrypt is a robust, adaptive password hashing function based on the Blowfish cipher. It is designed to be slow and computationally expensive, which protects against brute-force attacks and rainbow table lookups.
Because Bcrypt automatically generates a random salt and incorporates it into the final hash output. When verifying, the algorithm extracts this salt to compute the comparison.
A work factor of 10-12 is standard for modern applications. The goal is to make hashing take around 250-500ms on a typical server, frustrating attackers without slowing down legitimate logins.