why does concatenating bcrypt(salt, pw) with HMAC(salt, pw) make guessing fast?
Intuitively it seems like you'd still need to guess the bcrypt portion, making it no worse than just bcrypt.
Intuitively it seems like you'd still need to guess the bcrypt portion, making it no worse than just bcrypt.