From 09517318b87e39506cbcb3232a395ac7d43c25f5 Mon Sep 17 00:00:00 2001 From: Rose Hogenson Date: Tue, 23 Sep 2025 21:18:49 -0700 Subject: Use pbkdf2 for password hashing instead of sha512 --- cmd/finditers/finditers.go | 44 ++++++++++++++++++++++++++++++++++++++++++++ cmd/hashpw/hashpw.go | 34 ++++++++++++++++++++++++++++++++++ 2 files changed, 78 insertions(+) create mode 100644 cmd/finditers/finditers.go create mode 100644 cmd/hashpw/hashpw.go (limited to 'cmd') diff --git a/cmd/finditers/finditers.go b/cmd/finditers/finditers.go new file mode 100644 index 0000000..2a256c8 --- /dev/null +++ b/cmd/finditers/finditers.go @@ -0,0 +1,44 @@ +package main + +import ( + "encoding/hex" + "fmt" + "os" + "sort" + "testing" + "time" + + "gitlab.com/rhogenson/roseh.moe/internal/pwhash" +) + +var ( + iterations int + + salt, _ = hex.DecodeString("3fb84513fc3afcd6d3b230bf9ece91aaae2d2a99da17efbf7de83b21fafe3f08") +) + +func BenchmarkHashIter(b *testing.B) { + const password = "oboe shortness ether ideology undesired fresh freezable catching mashing glimpse" + for b.Loop() { + pwhash.HashIter(password, salt, iterations) + } +} + +func run() error { + for iterations = 8192; time.Duration(testing.Benchmark(BenchmarkHashIter).NsPerOp()) < 500*time.Millisecond; iterations *= 2 { + } + lo := iterations / 2 + hi := iterations + fmt.Println(lo + sort.Search(hi-lo, func(i int) bool { + iterations = lo + i + return time.Duration(testing.Benchmark(BenchmarkHashIter).NsPerOp()) > 500*time.Millisecond + })) + return nil +} + +func main() { + if err := run(); err != nil { + fmt.Fprintln(os.Stderr, err) + os.Exit(1) + } +} diff --git a/cmd/hashpw/hashpw.go b/cmd/hashpw/hashpw.go new file mode 100644 index 0000000..ffbdf79 --- /dev/null +++ b/cmd/hashpw/hashpw.go @@ -0,0 +1,34 @@ +package main + +import ( + "crypto/rand" + "fmt" + "os" + + "gitlab.com/rhogenson/roseh.moe/internal/pwhash" + "golang.org/x/term" +) + +func run() error { + fmt.Print("Enter password:") + password, err := term.ReadPassword(int(os.Stdin.Fd())) + fmt.Println() + if err != nil { + return err + } + salt := make([]byte, 32) + rand.Read(salt) + hashedPassword, err := pwhash.Hash(string(password), salt) + if err != nil { + return err + } + fmt.Printf("notepad-password=%x\nsalt=%x\n", hashedPassword, salt) + return nil +} + +func main() { + if err := run(); err != nil { + fmt.Fprintln(os.Stderr, err) + os.Exit(1) + } +} -- cgit v1.3.1