4 ms·
Using bcrypt to secure passwords in Perl
- draegtun 15y agoAlso a very similar post Safely Storing Passwords from a few days earlier on blogs.perl.org which includes a Dancer bcrypt plugin: http://blogs.perl.org/users/james_aitken/2011/07/safely-storing-passwords.html http://blogs.perl.org/users/james_aitken/2011/07/safely-stor...
- LoonyPandora 15y agoI also blogged about this topic on blogs.perl.org the other week with some code examples that work a little better [1]. Your code appears to work, but is subtly broken in a few ways. Firstly since you don't return the hash in the "standard" format ("$2a", "$", two digits, "$", salt as 22 base 64 digits, '.', and 31 base 64 digits for the pass), one can't tell what work factor was used to create the hash - making it hard to verify a password. Secondly the salt isn't sufficiently random, there are modules out there that provide more randomness for cryptographic applications such as this. It's nice to see people blogging about this kind of thing for perl, but it's important that the code is correct. [1] http://blogs.perl.org/users/james_aitken/2011/07/safely-storing-passwords.html http://blogs.perl.org/users/james_aitken/2011/07/safely-stor...
- geoffc 15y agoThanks for the feedback. I will make some changes.
- LoonyPandora 15y agoHave a look at Authen::Passphrase::BlowfishCrypt [1]. it handles a lot of my suggestions automatically and is more suited to your general-case than my code is. [1] http://search.cpan.org/~zefram/Authen-Passphrase-0.007/lib/Authen/Passphrase/BlowfishCrypt.pm http://search.cpan.org/~zefram/Authen-Passphrase-0.007/lib/A...
- geoffc 15y agoI have updated the code to use the standard storage format and switched to a better salt generator.
- tomjen3 15y agoAnd that is why I don't like bcrypt -- it is far too easily to screw something up in non-obvious ways.
- rimantas 15y agoYeah, at least by using md5 one can easily screw everything up in an obvious way.
- marshray 15y agoI think you were being sarcastic, but sometimes that is indeed an improvement.
- pyre 15y agoI think that point of the sarcasm was that using MD5 is the obvious screw-up.
- marshray 15y agoYes, I understand that. I was saying that an obviously screwed-up system is often better than a subtly screwed-up one. Nevertheless, a well-implemented MD5-based system could still be "less bad" than the buggy home-rolled bcrypt in that link.
- deleted 15y ago[deleted]
- alfiejohn_ 15y agoIt's a shame that the first comment was for a typo. Can't people get over these things?
- geoffc 15y agoYes but the second comment on the blog was great, truly an education in encryption for me.
- jrockway 15y agoNo, no, no. Just use Authen::Passphrase.