riverrun

riverrun

I’ve just released version 3 of Comeonin, a password hashing library.

The following small changes have been made:

  • changes to the NIF code to make it more scheduler-friendly
  • more information about Argon2, the winner of the 2015 Password Hashing Competition, in the documentation
  • now using elixir_make as the compiler

If you have any questions / issues, just let me know.

Showing Posts 23 to 14

danschultzer

danschultzer

Pow Core Team

Yeah, Argon2id is the best option atm. At least, SCrypt is better than BCrypt. In the vast majority of cases it doesn’t really matter since there are much easier ways to get passwords than cracking them.

I wrote about it in the production checklist for Pow with a link to this medium post that details the different popular password hashing options.

Argon2 won the Password Hashing Competition in 2015.

egeersoz

egeersoz

So which hashing algorithm is recommended for systems being designed today?

I’ve read some opinions stating that Argon2 might be better. For instance:

…but I figured I’d ask the Elixir community as well.

In what scenarios would Argon2 should actually be preferred over Bcrypt? The link posted above says “…and offline cracking is in the threat model.” In this context, does “offline cracking” mean the attacker somehow grabs a copy of your database and can attempt to crack the password hashes in it?

riverrun

riverrun OP

Version 5 has been released.

This version is an update based on this issue. Comeonin now provides two behaviours, Comeonin and Comeonin.PasswordHash, which can then be implemented by password hashing libraries.

Together with this update, argon2_elixir and bcrypt_elixir have been updated to version 2.0, and pbkdf2_elixir has been updated to version 1.0.

To update to the new versions, remove :comeonin from the deps function in your mix.exs file, update the hashing library to the latest version, and then edit the hashing functions as shown below:

Comeonin.Argon2.add_hash → Argon2.add_hash
Comeonin.Argon2.check_pass → Argon2.check_pass
Comeonin.Argon2.hashpwsalt → Argon2.hash_pwd_salt
Comeonin.Argon2.checkpw → Argon2.verify_pass
Comeonin.Argon2.dummy_checkpw → Argon2.no_user_verify

For more information see this guide.

If you have any questions / comments, please let me know.

riverrun

riverrun OP

Two things I would like to mention:

First, there is this issue about redesigning Comeonin. I can see arguments for and against the proposed changes, and I would welcome any feedback you might have. As Comeonin is widely used, I want to get as much feedback as I can before making a final decision.

Second, I have set up a patreon page to accept donations. I would like to stress that Comeonin, and the other libraries I maintain, are offered free of charge, but there are times when I cannot spend as much time on them as I would like. If I can receive some financial support, then I will be able to invest more time in their development.

riverrun

riverrun OP

A little explanation of some of the changes that came with version 4 of Comeonin – https://riverrun.github.io/projects/comeonin/2017/09/03/comeonin-v4.html

riverrun

riverrun OP

0.12 will be maintained for the foreseeable future, and it is very stable. It is just that it is not quite as scheduler friendly as the new version.

Making the new version 1.0 is meant to prevent developers updating to the new version by accident.

If you have any further questions, please feel free to ask.

NobbZ

NobbZ

Yupp, I am aware of that. And it is unclear how long at least security relevant patches will flow back to 0.12.

I’m just asking for a rough estimate of 0.12s end-of-life.

wmnnd

wmnnd

If the library is following Semantic Versioning, a jump from 0.x to 1.x indicates that the APIs are not compatible which is indeed the case here.

NobbZ

NobbZ

How long will you provide security backports to pre 1.0? Until OTP 19 fades from main distributions repositories?

It reads as quite a large jump… 0.12 to 1.0

riverrun

riverrun OP

I should have made it clearer that I’m not dropping support for the non-dirty scheduler version.

Version 1.0 supports dirty schedulers.

Version 0.12 is the ‘old’ version, which is still maintained and works fine, so if someone doesn’t want to update to Erlang 20, they can stay on the pre-1.0 version.

Where Next? Top

Trending in Announcing Top

type1fool
WebAuthnLiveComponent WebAuthnComponents See this post about renaming the package. Passwordless authentication for Phoenix LiveView app...
New
GenericJam
Edit: 2026 May 15 - This post is archived. Mob is alive!! Main docs: mob v0.7.11 — Documentation A bit of explanation for the slightly c...
New
woylie
I released Doggo, a collection of unstyled Phoenix components. https://github.com/woylie/doggo Features Unstyled Phoenix components....
New
ahamez
Hi everyone, I’ve been working on this protobuf library for 3 years. We use it in the company I work for, EasyMile, to communicate with ...
New
garrison
Hobbes is a low-level distributed database for the Elixir programming language. Hobbes provides a simple, safe, and scalable storage lay...
New
kip
I’ll shortly be launching Text, a nascent text analysis library. Current functionality In this early version (not ready for prime time) ...
New
kip
Following on from my CLDR lbraries I started work on Unicode transforms. But like everything related to CLDR there is a lot of yak-shavin...
New

Other Trending Topics Top

mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
budgie
A little off-topic, but I feel like people here have a good head on their shoulders. I used to be quite good at making software. Was luc...
New
KristerV
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
webofbits
With AI doing more of the implementation work, I’ve been wondering how much coding I should deliberately keep doing myself. My main conc...
#ai
New
budgie
I love Elixir. It’s one of 2 programming languages I’ve ever fallen in love with. But I don’t use it anymore. Serverless was the promis...
New
type1fool
I just stumbled on a newly redesigned elixir-lang.org. :tada: It looks like @Software_Mansion did the work, and I think it is generally a...
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews