drhwb470572 2013-08-31 07:23
浏览 67
已采纳

Golang / App Engine-安全地哈希用户密码

I have typically used the bcrypt library to do password hashing, but am unable to do so because of the library's use of syscall. I have also tried scrypt. What other ways are secure, and which would be the best way?

  • 写回答

1条回答 默认 最新

  • doushe2513 2013-11-07 04:43
    关注

    Have a look at go.crypto. It offers support for pbkdf2 and bcrypt. Both implementations are purely written in Go and should work on GAE just fine.

    The most simple to use is probably bcrypt. To get the package run:

    go get golang.org/x/crypto/bcrypt
    

    Example usage:

    import "golang.org/x/crypto/bcrypt" 
    
    func clear(b []byte) {
        for i := 0; i < len(b); i++ {
            b[i] = 0;
        }
    }
    
    func Crypt(password []byte) ([]byte, error) {
        defer clear(password)
        return bcrypt.GenerateFromPassword(password, bcrypt.DefaultCost)
    }
    
    ctext, err := Crypt(pass)
    
    if err != nil {
        log.Fatal(err)
    }
    
    fmt.Println(string(ctext))
    

    The output will be something like this:

    $2a$10$sylGijT5CIJZ9ViJsxZOS.IB2tOtJ40hf82eFbTwq87iVAOb5GL8e
    

    If you want simply the hash, use pbkdf2. Example:

    import "golang.org/x/crypto/pbkdf2"
    
    func HashPassword(password, salt []byte) []byte {
        defer clear(password)
        return pbkdf2.Key(password, salt, 4096, sha256.Size, sha256.New)
    }
    
    pass := []byte("foo")
    salt := []byte("bar")
    
    fmt.Printf("%x
    ", HashPassword(pass, salt))
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 这种微信登录授权 谁可以做啊
  • ¥15 请问我该如何添加自己的数据去运行蚁群算法代码
  • ¥20 用HslCommunication 连接欧姆龙 plc有时会连接失败。报异常为“未知错误”
  • ¥15 网络设备配置与管理这个该怎么弄
  • ¥20 机器学习能否像多层线性模型一样处理嵌套数据
  • ¥20 西门子S7-Graph,S7-300,梯形图
  • ¥50 用易语言http 访问不了网页
  • ¥50 safari浏览器fetch提交数据后数据丢失问题
  • ¥15 matlab不知道怎么改,求解答!!
  • ¥15 永磁直线电机的电流环pi调不出来