
SANS Stormcast Thursday, March 12th, 2026: Zombie Zip;
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
How salt placement broke authentication
Johannes explains that prepending long salts (>72 bytes) causes bcrypt to ignore the password, enabling authentication bypass.
Play episode from 03:56
Transcript


