4 ms·
> ... developer education remain essential for realizing Argon2's theoretical advantages. > 46.6% of deployments use weaker-than-OWASP parameters. Sounds like
by palantird 1y ago
> ... developer education remain essential for realizing Argon2's theoretical advantages.
> 46.6% of deployments use weaker-than-OWASP parameters.
Sounds like a job for better default parameter values.
I'm willing to bet most startups just install the default argon2 (or password hashing) library in their language of choice and don't jump head-first into the rabbithole of fine-tuning argon2 parameters unless a contract or certification depend on it.
- swiftcoder 1y agoThe documentation on this is... uh... intimidating? I come away from this with the sense that I need to learn a whole lot about cryptography to make a good decision here: https://argon2-cffi.readthedocs.io/en/stable/parameters.html https://argon2-cffi.readthedocs.io/en/stable/parameters.html
- luizfelberti 1y agoDo not reference these kinds of docs whenever you need practical, actionable advice. They serve their purpose, but are for a completely different kind of audience. For anyone perusing this thread, your first resource for this kind of security advice should probably be the OWASP cheatsheets which is a living set of documents that packages current practice into direct recommendations for implementers. Here's what it says about tuning Argon2: https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#argon2id https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor...
- tptacek 1y agoIt's been a couple years since I've looked but the track record of OWASP for cryptography advice has been pretty dismal.
- linsomniac 1y agoDo you have a better recommendation? I feel bad for OWASP. They're doing the lords work, but seem to have a shoestring budget.
- rubendev 1y agoThe OWASP ASVS appendix on Cryptography is one of the best and concise resources I know for this kind of thing: https://github.com/OWASP/ASVS/blob/master/5.0/en/0x92-Appendix-C_Cryptography.md#hash-functions-for-password-storage https://github.com/OWASP/ASVS/blob/master/5.0/en/0x92-Append...
- akerl_ 1y agoI’d wager that something like 90% of developers who look at that page should close the tab instead of reading any of it. If you’re building a system and need crypto… pick the canonical library for the ecosystem or language you’re working in. Don’t try to build your own collection of primitives.
- rubendev 1y agoYes I fully agree. I’m a big fan of libraries like Google Tink that make you pick a use case and use the best implementation for that use case with built in crypto agility. Most crypto libraries are not built like that however. They just give you a big pile of primitives/algorithms to choose from. Then frameworks get built on top of that, not always taking into account best practices, and leave people that are serious about security the job of making sure the implementation is secure. This is the point where you need something like ASVS.
- akerl_ 1y agoWhat language today still doesn't have a de facto simplified toolbox for wrapping crypto operations? If you're a developer, and you start trying to perform crypto operations for your service and the library you chose is making you question which cipher, what KDF parameters, or what DH group you want, that is 100% a red flag and you should promptly stop using that crypto library.