HORIZON HASKELLDocslts/ghc-9.10.xc74966e2026-09-27Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27

Modulepassword-3.0.4.0Haskell2010

Data.Password.PBKDF2

PBKDF2

The PBKDF2 algorithm is one of the oldest and most solid password algorithms out there. It has also, however, been shown to be the least secure out of all major password algorithms. The main reason for this is that it doesn't make use of any memory cost or other method of making it difficult for specialized hardware attacks, like GPU cracking attacks.

It is still, however, used all over the world, since it has been shown to be a very reliable way to encrypt passwords. And it is most definitely better than trying to develop a password algorithm on your own, or god-forbid, not using any encryption on your stored passwords.

Other algorithms

Seeing as PBKDF2 is shown to be very weak in terms of protection against GPU cracking attacks, it is generally advised to go with Bcrypt, if not Scrypt or Argon2. When unsure, Bcrypt would probably be the safest option, as it has no memory cost which could become a problem if not properly calibrated to the machine doing the password verifications.

  • 7 types
  • 9 values
  • Packagepassword-3.0.4.0
  • Exports16
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourcePBKDF2.hs
datadata PBKDF2
#

Phantom type for PBKDF2

Plain-text Password

2 declarations
newtypenewtype Password
#

A plain-text password.

This represents a plain-text password that has NOT been hashed.

You should be careful with Password. Make sure not to write it to logs or store it in a database.

You can construct a Password by using the mkPassword function or as literal strings together with the OverloadedStrings pragma (or manually, by using fromString on a String). Alternatively, you could also use some of the instances in the password-instances library.

Instances2Show, IsString
  • Show PasswordDefined in password-types-1.0.0.0 · Data.Password.Types

    CAREFUL: Show-ing a Password will always print "**PASSWORD**"

    Example1 expression
    show ("hello" :: Password)"**PASSWORD**"
  • IsString PasswordDefined in password-types-1.0.0.0 · Data.Password.Types

Hash Passwords (PBKDF2)

2 declarations
newtypenewtype PasswordHash a
#

A hashed password.

This represents a password that has been put through a hashing function. The hashed password can be stored in a database.

Instances4Eq, Ord, Read, Show
  • Eq (PasswordHash a)Defined in password-types-1.0.0.0 · Data.Password.Types
  • Ord (PasswordHash a)Defined in password-types-1.0.0.0 · Data.Password.Types
  • Read (PasswordHash a)Defined in password-types-1.0.0.0 · Data.Password.Types
  • Show (PasswordHash a)Defined in password-types-1.0.0.0 · Data.Password.Types

Verify Passwords (PBKDF2)

2 declarations

Check a Password against a PasswordHash PBKDF2.

Returns PasswordCheckSuccess on success.

Example3 expressions
let pass = mkPassword "foobar"passHash <- hashPassword passcheckPassword pass passHashPasswordCheckSuccess

Returns PasswordCheckFail if an incorrect Password or PasswordHash PBKDF2 is used.

Example2 expressions
let badpass = mkPassword "incorrect-password"checkPassword badpass passHashPasswordCheckFail

This should always fail if an incorrect password is given.

Property
\(Blind badpass) -> let correctPasswordHash = hashPasswordWithSalt testParams salt "foobar" in checkPassword badpass correctPasswordHash == PasswordCheckFail
datadata PasswordCheck
#

The result of checking a password against a hashed version. This is returned by the checkPassword functions.

Constructors

  • PasswordCheckSuccess

    The password check was successful. The plain-text password matches the hashed password.

  • PasswordCheckFail

    The password check failed. The plain-text password does not match the hashed password.

Instances3Eq, Read, Show

Hashing Manually (PBKDF2)

5 declarations

Default parameters for the PBKDF2 algorithm.

Example1 expression
defaultParamsPBKDF2Params {pbkdf2Salt = 16, pbkdf2Algorithm = PBKDF2_SHA512, pbkdf2Iterations = 25000, pbkdf2OutputLength = 64}
datadata PBKDF2Params
#

Parameters used in the PBKDF2 hashing algorithm.

Constructors

Instances2Eq, Show

Hashing with salt (DISADVISED)

Hashing with a set Salt is almost never what you want to do. Use hashPassword or hashPasswordWithParams to have automatic generation of randomized salts.

Hash a password with the given PBKDF2Params and also with the given Salt instead of a randomly generated salt using pbkdf2Salt from PBKDF2Params. (cf. hashPasswordWithParams) Using hashPasswordWithSalt is strongly disadvised and hashPasswordWithParams should be used instead. Never use a static salt in production applications!

Example2 expressions
let salt = Salt "abcdefghijklmnop"hashPasswordWithSalt defaultParams salt (mkPassword "foobar")PasswordHash {unPasswordHash = "sha512:25000:YWJjZGVmZ2hpamtsbW5vcA==:JRElYYrOMe9OIV4LDxaLTgO9ho8fFBVofXoQcdngi7AcuH6Amvmlj2B0y6y1UtQciXXBepSCS+rpy8/vDDQvoA=="}

(Note that we use an explicit Salt in the example above. This is so that the example is reproducible, but in general you should use hashPassword. hashPassword (and hashPasswordWithParams) generates a new Salt everytime it is called.)

newtypenewtype Salt a
#

A salt used by a hashing algorithm.

Constructors

Instances2Eq, Show
  • Eq (Salt a)Defined in password-types-1.0.0.0 · Data.Password.Types
  • Show (Salt a)Defined in password-types-1.0.0.0 · Data.Password.Types

Unsafe debugging function to show a Password

1 declaration

This is an unsafe function that shows a password in plain-text.

Example1 expression
unsafeShowPassword ("foobar" :: Password)"foobar"

You should generally not use this function in production settings, as you don't want to accidentally print a password anywhere, like logs, network responses, database entries, etc.

This will mostly be used by other libraries to handle the actual password internally, though it is conceivable that, even in a production setting, a password might have to be handled in an unsafe manner at some point.

Setup for doctests.

0 declarations
Example2 expressions
:set -XFlexibleInstances:set -XOverloadedStrings

Import needed libraries.

Example4 expressions
import Data.Password.Typesimport Data.ByteString (pack)import Test.QuickCheck (Arbitrary(arbitrary), Blind(Blind), vector)import Test.QuickCheck.Instances.Text ()
Example4 expressions
instance Arbitrary (Salt a) where arbitrary = Salt . pack <$> vector 16instance Arbitrary Password where arbitrary = fmap mkPassword arbitrarylet testParams = defaultParams{ pbkdf2Iterations = 5000 }let salt = Salt "abcdefghijklmnop"