6 ms·
Introducing Authgasm: "Rails authentication done right".
- tptacek 18y agoSigh. Just what we needed; another authentication plugin... that uses crackable salted SHA256 to store web passwords. Of course, it provides a plugin interface --- including, inexplicably, support for symmetrically (ie, recoverably) encrypting passwords. What it doesn't do is support bcrypt-ruby, which is the only correct answer to this problem.
- mhidalgo 18y agocould you use bcrypt instead of something like the restful-authentication plugin ?
- jonny_noog 18y agoThanks, I'd not yet heard of bcrypt. But if the OpenBSD guys are down with it, then it must be worth a go. This stuff is why I come here. :)
- sanswork 18y agoYou would know better than me and almost certainly keep more in tune with the cutting edge on this but how easy is it exactly to crack a salted SHA256 password?
- tptacek 18y agoYou want your authentication hash to be slow. Password tests are never in your 80/20 performance hot spot. The faster a single password test is, the faster it is to run an entire dictionary through that test function looking for a matching hash. SHA256 is slower than SHA1, which is slower than MD5. But in the grand scheme of things, SHA256 is fast. It's designed to be fast --- fast enough to run on a per-packet basis in secure network protocols. Bcrypt is designed to be slow. So is "stretched" SHA256, which is simply SHA256 iterated thousands of times. Both these schemes are much harder to crack than simply hashing a password with SHA256. The trouble I have here is that authentication is one part of your application you don't want to mess around with, but already someone here said "I'm going to try this just because the name is awesome". Forget the cosmetics. There's only one right answer to this problem.
- jonny_noog 18y agoI did a bit of looking into bcrypt-ruby after hearing about it here. It sounds good, I like the idea of the "cost" attribute. However, I note that Coda Hale appears to have no interest in supporting his bcrypt-ruby gem for Windows. On his blog he says essentially that he doesn't use Windows and hence has no motivation to put any time into getting a pre-compiled bcrypt-ruby to work on Windows. I can totally understand where he's coming from and as I do all my dev work on Debian Linux, it's not a problem for me personally. But my partner is a Windows user and it would be a problem for him. The closest I have found to instructions on getting bcrypt-ruby compiled on Windows are from the bcrypt-ruby README: You‘ll need a working compiler. (Win32 folks should use Cygwin or um, something else.) So does this mean that my partner would then have to use the Cygwin environment for all his dev work from this point on? And a random comment from Coda Hale's blog: bcrypt seems to work with the Windows One-Click-Installer too. It was easy to compile it with MinGW (I just had to define the missing types u_int8_t, u_int16_t, and u_int32_t). All your tests pass. So you might consider to offer a precompiled version for us Windows users. I am not a C programmer (getting more experience with a compiled language is on my todo list, just no time as yet) nor am I a security expert. My past experience with compiling stuff basically extends to typing "make" and "make install". I don't really understand what "I just had to define the missing types u_int8_t, u_int16_t, and u_int32_t" means. So as much as I would like to try and incorporate bcrypt-ruby into my current Rails project, I can't really justify this added overhead of getting it to work on my partners Windows dev box with near zero support. If anyone has more info, that would be great. But otherwise, I will - for now - be sticking with salted SHA256.
- binarylogic 18y agoI am the creator of this plugin. Who cares about the name. I wanted something unique that would get people's attention and return unique content when searching. I also thought it was funny. People need to lighten up a little bit if the name bothers them. It's not like I put the name "authgasm" in helpers that you have to use all over your application. It sits in your plugin dir, that's all. Anyways, regarding encryption. You can encrypt the password any way you want. Use bcrypt-ruby if you want. It would take no time at all to set up. Checkout the acts_as_authentic documentation. You can provide your own "crypto provider" and have it do whatever you want. Lastly, I don't use Sha256 straight up. I add in salt. So reverse lookups are out of the question. Your last option is brute force. There is no encryption / hashing algorithm that is safe from brute force. Granted some might slow it down more than others, all that is doing is setting up more hurdles to jump, not 100% secure. But I really like bcrypt, I'll look into it and maybe switch it to the default crypto provider. But, I really think for anything that is not being used in the NSA, Sha256 + salt would work just fine.
- siong1987 18y agoI really like the name. I may try it out just because of the name. Authgasm.
- binarylogic 18y agoAwesome, you shouldn't even consider using a plugin / gem unless it has a good name. The same applies with books. Unless you like title / cover you shoudn't read it.
- sunkencity 18y agoI would be very happy if they could move in some standard user authentication into rails. Tired of the stream of plugins that become abandonware in a couple of months.
- catch23 18y agowell most of the authentication plugins are only 100 lines of code or so. Even if the plugin author dies in a freak accident involving toothpicks, you should have no trouble maintaining the plugin yourself.
- Frabjous-Dey 18y agoAre they all pretty much the same? Is there currently a reigning/most popular plugin floating around?
- binarylogic 18y agoAlso, thanks to github, if a plugin is popular enough it never really gets abandoned. Look at the engines plugin. The author of that plugin rarely does anything to it, but people fork it and keep it up-to-date.
- binarylogic 18y agoThis discussion is moot since Authlogic easily supports BCrypt: http://www.binarylogic.com/2008/11/22/storing-nuclear-launch-codes-in-your-app-enter-bcrypt-for-authlogic http://www.binarylogic.com/2008/11/22/storing-nuclear-launch...