Package3.0.4.0Data
password
Hashing and checking of passwords
- Version3.0.4.0
- CategoryData
- LicenceBSD-3-Clause
- AuthorDennis Gosnell, Felix Paulusma
- Maintainercdep.illabout@gmail.com, felix.paulusma@gmail.com
- Homepagegithub.com/cdepillabout/password/tree/master/password#readme
- Pinned byhackage password 3.0.4.0
- Sourcehackage.haskell.org/package/password-3.0.4.0
Modules
5 modules- Data.Password.Argon217Argon2 Argon2 is probably the newest password algorithm out there. Argon2 was
- Data.Password.Bcrypt14bcrypt The bcrypt algorithm is a popular way of hashing passwords.
- Data.Password.PBKDF216PBKDF2 The PBKDF2 algorithm is one of the oldest and most solid password
- Data.Password.Scrypt15scrypt The scrypt algorithm is a fairly new one. First published
- Data.Password.Validate25Password Validation It is common for passwords to have a set of requirements. The most obvious
Description
A library providing functionality for working with plain-text and hashed passwords with different types of algorithms.
Every supported hashing algorithm has its own module (e.g. Data.Password.Bcrypt) which exports its own hashPassword and checkPassword functions, as well as all the types and functions in this module. If you are not sure about the specifics of an algorithm you want to use, you can rest assured that by using the hashPassword function of the respective algorithm you are not making any big mistakes, security-wise.
Of course, if you know what you're doing and you want more fine-grained control over the hashing function, you can adjust it using the hashPasswordWithParams function of the respective algorithm.
Generally, the most "secure" algorithm is believed to be Argon2, then scrypt, then bcrypt, and lastly PBKDF2. bcrypt and PBKDF2 are the most established algorithms, so they have been tried and tested, though they both lack a memory cost, and therefore have a greater vulnerability to specialized hardware attacks.
When choosing an algorithm, and you have no idea which to pick, just go for bcrypt if your password does not need the highest security possible. It's still a fine way for hashing passwords, and the cost is easily adjustable if needed. If your needs do require stronger protection, you should find someone who can advise you on this topic. (And if you're already knowledgeable enough, you know what to do)
Depends on
8 packages- base-4.20.2.0with GHC
- base64-1.0in this set
- bytestring-0.12.2.0with GHC
- cryptonite-0.30in this set
- memory-0.18.0in this set
- password-types-1.0.0.0in this set
- template-haskell-2.22.0.0with GHC
- text-2.1.3with GHC
Used by in this set · 0
Nothing in this set depends on it.