From 09517318b87e39506cbcb3232a395ac7d43c25f5 Mon Sep 17 00:00:00 2001 From: Rose Hogenson Date: Tue, 23 Sep 2025 21:18:49 -0700 Subject: Use pbkdf2 for password hashing instead of sha512 --- internal/pwhash/pwhash.go | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 internal/pwhash/pwhash.go (limited to 'internal') diff --git a/internal/pwhash/pwhash.go b/internal/pwhash/pwhash.go new file mode 100644 index 0000000..a17ed2e --- /dev/null +++ b/internal/pwhash/pwhash.go @@ -0,0 +1,22 @@ +package pwhash + +import ( + "crypto/pbkdf2" + "crypto/sha256" + "crypto/sha512" +) + +const defaultIterations = 3670016 // from cmd/finditers + +func HashIter(password string, salt []byte, iter int) ([]byte, error) { + return pbkdf2.Key(sha256.New, password, salt, iter, 32) +} + +func Hash(password string, salt []byte) ([]byte, error) { + hashed, err := HashIter(password, salt, defaultIterations) + if err != nil { + return nil, err + } + sha := sha512.Sum512(hashed) + return sha[:], nil +} -- cgit v1.3.1