I work with C#, Java, Python Go and JS on backends a lot and no other language I worked with had such a simple but secure API.
Still, a pragmatic answer and, given PHP started life as a web framework, fitting :).
func GenerateFromPassword(password []byte, cost int) ([]byte, error)
func CompareHashAndPassword(hashedPassword, password []byte) error
[from golang.org/x/crypto/bcrypt] from django.contrib.auth.models import User
u = User.objects.get(username='john')
u.set_password('new password')
u.save()
And here is the code which does all the magic - [1]. You can also generate nice passwords [2], use many available different hashers [3] Or write your own [4][0] - https://docs.djangoproject.com/en/dev/topics/auth/default/#c...
[1] - https://github.com/django/django/blob/stable/1.10.x/django/c... and https://github.com/django/django/blob/stable/1.10.x/django/c...
[2] - https://docs.djangoproject.com/en/dev/topics/auth/customizin...
[3] - https://docs.djangoproject.com/en/dev/topics/auth/passwords/...
[4] - https://docs.djangoproject.com/en/dev/topics/auth/passwords/...
Note that of course the password algorithms are typed, so this doesn't cause a problem in the corner case that a user's password is a sha1 hash of something else.
[0] - https://docs.djangoproject.com/en/dev/topics/auth/passwords/...
PBEKeySpec spec = new PBEKeySpec(password.toCharArray(), salt.getBytes(StandardCharsets.UTF_8), iterations, digestSize)
SecretKeyFactory skf = SecretKeyFactory.getInstance("PBKDF2WithHmacSHA256")
byte[] hash = skf.generateSecret(spec).getEncoded()
ant then using MessageDigest.isEqual (on newer jvm, older ones had a bug up to 6 45 or so) to compare the passwords.well the biggest problem is probably generating a truly random salt with SecureRandom, which will slow down your program if used incorrect.