Node has decent support for WebCrypto, for example, which renders all usages of node:crypto obsolete.
At this point, I’d also argue that anything not promoting PassKeys as the default method is on the wrong track.
Node has decent support for WebCrypto, for example, which renders all usages of node:crypto obsolete.
At this point, I’d also argue that anything not promoting PassKeys as the default method is on the wrong track.
CF workers support it: https://developers.cloudflare.com/workers/runtime-apis/web-c...
Most browsers support it: https://developer.mozilla.org/en-US/docs/Web/API/Crypto
None of the hashes available in webcrypto's digest() are suitable for storing passwords (eg it doesn't support argon2, scrypt, bcrypt, or PBKDF2). They are all SHA family hashes.
https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypt...
You can use PBKDF2 through the deriveKey() function. So you could use that to store passwords. However, this is the least preferred of the acceptable algorithms, and is only recommended for use in scenarios where you must follow a standard that mandates the use of PBKDF2.
Passwords are dumb for most use cases. They’re okay if you follow best practices, the thing is 99% of people don’t. So most people re-use passwords, and if asked to create new ones they append a character or something ineffective.
No thanks, just do a LiDar scan of my face and get me into Netflix please.
This may be dependent on your social. Everyone I know uses password managers, even at work. So they have different passwords for every account and browser/phone extensions or apps to fill them in.
The only one is generally password hashing. At this point, I just run up a service binding to a rust worker and hash it over there.