> That's a problem unrelated to hashing.
It (poor implementation) is definitely related to implementing pepper on top of a secure password hash, though, which everybody is already doing differently.
> I would avoid using any particular symmetric algorithm twice. Otherwise if you have an example of algorithm chaining that can weaken security beyond the weakest link, I would love to see it. (Not that I think nesting is a great idea.)
“algorithm” is, again, really vague. (So is “nesting”.) But for something contrived and not snarky, here:
h = sha512_hex(password)
sha512_hex(bcrypt(h, gen_salt()) +
bcrypt(h, gen_salt()) +
bcrypt(h, gen_salt()) +
bcrypt(h, gen_salt()))
The weakest link here is 374 bits (4 bcrypts), but the output is 288.