I had do decide on a hashing scheme recently and ended up going with Bcrypt just because of how new Scrypt is.
I had do decide on a hashing scheme recently and ended up going with Bcrypt just because of how new Scrypt is.
IMHO, MITM would be better defended against using HSTS, certificate pinning, and perhaps DNSSEC.
I assume the extra client-side hashing is done to keep the plaintext passwords out of the application memory, not protect it in transit.
To clarify, this is just an assumption. I have not read up on the topic nor do I claim to be a security expert. This is just what came to mind when I had the same thought as you.
Anyone else know for sure?
Meme reference aside, this is actually a sane way to do things.
https://paragonie.com/book/pecl-libsodium/read/09-recipes.md...
This is the scheme that I'm using for one of my projects. :)
The work factor of a password database can be changed easily, either by re-hashing every time someone with the old scheme logs in, or by hashing all the hashes more.
// Returns binary data
shaPass = crypto.sha256(userPassword)
// returns an scrypt password
crypto.bcrypt(shaPass)
I've seen many people pass binary data into functions that will terminate reading the string at a null byte. This obviously limits the strength of the number of bytes before a null byte is hit in the binary data (mostly only concerns PHP and C).Just noticed someone else posted the ircmaxwell blog, which is the best writing on this topic.