However, I note that Coda Hale appears to have no interest in supporting his bcrypt-ruby gem for Windows. On his blog he says essentially that he doesn't use Windows and hence has no motivation to put any time into getting a pre-compiled bcrypt-ruby to work on Windows.
I can totally understand where he's coming from and as I do all my dev work on Debian Linux, it's not a problem for me personally. But my partner is a Windows user and it would be a problem for him.
The closest I have found to instructions on getting bcrypt-ruby compiled on Windows are from the bcrypt-ruby README:
You‘ll need a working compiler. (Win32 folks should use Cygwin or um, something else.)
So does this mean that my partner would then have to use the Cygwin environment for all his dev work from this point on?
And a random comment from Coda Hale's blog:
bcrypt seems to work with the Windows One-Click-Installer too. It was easy to compile it with MinGW (I just had to define the missing types u_int8_t, u_int16_t, and u_int32_t). All your tests pass. So you might consider to offer a precompiled version for us Windows users.
I am not a C programmer (getting more experience with a compiled language is on my todo list, just no time as yet) nor am I a security expert. My past experience with compiling stuff basically extends to typing "make" and "make install". I don't really understand what "I just had to define the missing types u_int8_t, u_int16_t, and u_int32_t" means.
So as much as I would like to try and incorporate bcrypt-ruby into my current Rails project, I can't really justify this added overhead of getting it to work on my partners Windows dev box with near zero support.
If anyone has more info, that would be great. But otherwise, I will - for now - be sticking with salted SHA256.