mirror of
https://github.com/restic/restic.git
synced 2026-10-08 03:17:12 +00:00
Lock simple-scrypt library to master branch
The master branch includes a fix for i386, otherwise the calibration panics. See https://github.com/restic/restic/issues/676 for details.
This commit is contained in:
1 parent
4477d76f03
commit
41c35b2218
7 files changed
+148
-20
No files matched your search
+10
-7
@@ -1,13 +1,16 @@
|
||||
language: go
|
||||
|
||||
sudo: false
|
||||
|
||||
go:
|
||||
- 1.2
|
||||
- 1.3
|
||||
- 1.4
|
||||
- 1.5
|
||||
- tip
|
||||
install:
|
||||
- go get golang.org/x/tools/cmd/vet
|
||||
- 1.2
|
||||
- 1.3
|
||||
- 1.4
|
||||
- 1.5
|
||||
- 1.6
|
||||
- 1.7
|
||||
- tip
|
||||
|
||||
script:
|
||||
- go get -t -v ./...
|
||||
- diff -u <(echo -n) <(gofmt -d -s .)
|
||||
|
||||
+51
-6
@@ -16,6 +16,14 @@ The API closely mirrors Go's [bcrypt](https://golang.org/x/crypto/bcrypt)
|
||||
library in an effort to make it easy to migrate—and because it's an easy to grok
|
||||
API.
|
||||
|
||||
## Installation
|
||||
|
||||
With a [working Go toolchain](https://golang.org/doc/code.html):
|
||||
|
||||
```sh
|
||||
go get -u github.com/elithrar/simple-scrypt
|
||||
```
|
||||
|
||||
## Example
|
||||
|
||||
simple-scrypt doesn't try to re-invent the wheel or do anything "special". It
|
||||
@@ -95,14 +103,51 @@ func main() {
|
||||
}
|
||||
```
|
||||
|
||||
## TO-DO:
|
||||
## Automatically Determining Parameters
|
||||
|
||||
The following features are planned. PRs are welcome.
|
||||
Thanks to the work by [tgulacsi](https://github.com/tgulacsi), you can have simple-scrypt
|
||||
automatically determine the optimal parameters for you (time vs. memory). You should run this once
|
||||
on program startup, as calibrating parameters can be an expensive operation.
|
||||
|
||||
- [x] Tag a release build.
|
||||
- [x] Automatically calculate "optimal" values for N, r, p similar [to the Ruby scrypt library](https://github.com/pbhogan/scrypt/blob/master/lib/scrypt.rb#L97-L146)
|
||||
e.g. `func Calibrate(duration int, mem int, fallback Params) (Params, error)`
|
||||
- contributed thanks to @tgulacsi.
|
||||
```go
|
||||
var params scrypt.Params
|
||||
|
||||
func main() {
|
||||
var err error
|
||||
// 500ms, 64MB of RAM per hash.
|
||||
params, err = scrypt.Calibrate(500*time.Millisecond, 64, Params{})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
...
|
||||
}
|
||||
|
||||
func RegisterUserHandler(w http.ResponseWriter, r *http.Request) {
|
||||
err := r.ParseForm()
|
||||
if err != nil {
|
||||
http.Error(w, err.Error(), http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
|
||||
// Make sure you validate: not empty, not too long, etc.
|
||||
email := r.PostFormValue("email")
|
||||
pass := r.PostFormValue("password")
|
||||
|
||||
// Use our calibrated parameters
|
||||
hash, err := scrypt.GenerateFromPassword([]byte(pass), params)
|
||||
if err != nil {
|
||||
http.Error(w, err.Error(), http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
|
||||
// Save to DB, etc.
|
||||
}
|
||||
```
|
||||
|
||||
Be aware that increasing these, whilst making it harder to brute-force the resulting hash, also
|
||||
increases the risk of a denial-of-service attack against your server. A surge in authenticate
|
||||
attempts (even if legitimate!) could consume all available resources.
|
||||
|
||||
## License
|
||||
|
||||
|
||||
+80
@@ -0,0 +1,80 @@
|
||||
{
|
||||
"name": "elithrar/simple-scrypt",
|
||||
"version": "0.1.4",
|
||||
"libraries": {
|
||||
"xv": "^1.1.25"
|
||||
},
|
||||
"title": "simple-scrypt",
|
||||
"branch": "",
|
||||
"style": {
|
||||
"name": "Williamsburg",
|
||||
"componentSet": {
|
||||
"nav": "nav/BasicNav",
|
||||
"header": "header/LightBannerHeader",
|
||||
"article": "article/ReaderArticle",
|
||||
"footer": "footer/BasicFooter"
|
||||
},
|
||||
"fontFamily": "Montserrat, sans-serif",
|
||||
"heading": {
|
||||
"fontWeight": 600,
|
||||
"letterSpacing": "0.1em"
|
||||
},
|
||||
"colors": {
|
||||
"text": "#666666",
|
||||
"background": "#fff",
|
||||
"primary": "#0099e0",
|
||||
"secondary": "#ab61ff",
|
||||
"highlight": "#f7b",
|
||||
"muted": "#2b2d70",
|
||||
"border": "#ccd"
|
||||
}
|
||||
},
|
||||
"content": [
|
||||
{
|
||||
"component": "nav",
|
||||
"links": [
|
||||
{
|
||||
"href": "https://github.com/elithrar/simple-scrypt",
|
||||
"text": "GitHub"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"component": "header",
|
||||
"heading": "simple-scrypt",
|
||||
"subhead": "A convenience library for generating, comparing and inspecting password hashes using the scrypt KDF in Go.",
|
||||
"children": [
|
||||
{
|
||||
"component": "ui/TweetButton",
|
||||
"text": "simple-scrypt: A convenience library for generating, comparing and inspecting password hashes using the scrypt KDF in Go.",
|
||||
"url": null
|
||||
},
|
||||
{
|
||||
"component": "ui/GithubButton",
|
||||
"user": "elithrar",
|
||||
"repo": "simple-scrypt"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"component": "article",
|
||||
"metadata": {
|
||||
"source": "github.readme"
|
||||
},
|
||||
"html": "\n<p><a href=\"https://godoc.org/github.com/elithrar/simple-scrypt\"><img src=\"https://godoc.org/github.com/elithrar/simple-scrypt?status.svg\"></a> <a href=\"https://travis-ci.org/elithrar/simple-scrypt\"><img src=\"https://travis-ci.org/elithrar/simple-scrypt.svg?branch=master\"></a></p>\n<p>simple-scrypt provides a convenience wrapper around Go's existing\n<a href=\"http://golang.org/x/crypto/scrypt\">scrypt</a> package that makes it easier to\nsecurely derive strong keys ("hash user passwords"). This library allows you to:</p>\n<ul>\n<li>Generate a scrypt derived key with a crytographically secure salt and sane\ndefault parameters for N, r and p.</li>\n<li>Upgrade the parameters used to generate keys as hardware improves by storing\nthem with the derived key (the scrypt spec. doesn't allow for this by\ndefault).</li>\n<li>Provide your own parameters (if you wish to).</li>\n</ul>\n<p>The API closely mirrors Go's <a href=\"https://golang.org/x/crypto/bcrypt\">bcrypt</a>\nlibrary in an effort to make it easy to migrate—and because it's an easy to grok\nAPI.</p>\n<h2>Installation</h2>\n<p>With a <a href=\"https://golang.org/doc/code.html\">working Go toolchain</a>:</p>\n<pre>go get -u github.com/elithrar/simple-scrypt</pre><h2>Example</h2>\n<p>simple-scrypt doesn't try to re-invent the wheel or do anything "special". It\nwraps the <code>scrypt.Key</code> function as thinly as possible, generates a\ncrytographically secure salt for you using Go's <code>crypto/rand</code> package, and\nreturns the derived key with the parameters prepended:</p>\n<pre><span class=\"hljs-keyword\">package</span> main\n\n<span class=\"hljs-keyword\">import</span>(\n <span class=\"hljs-string\">"fmt"</span>\n <span class=\"hljs-string\">"log"</span>\n\n <span class=\"hljs-string\">"github.com/elithrar/simple-scrypt"</span>\n)\n\n<span class=\"hljs-function\"><span class=\"hljs-keyword\">func</span> <span class=\"hljs-title\">main</span><span class=\"hljs-params\">()</span></span> {\n <span class=\"hljs-comment\">// e.g. r.PostFormValue("password")</span>\n passwordFromForm := <span class=\"hljs-string\">"prew8fid9hick6c"</span>\n\n <span class=\"hljs-comment\">// Generates a derived key of the form "N$r$p$salt$dk" where N, r and p are defined as per</span>\n <span class=\"hljs-comment\">// Colin Percival's scrypt paper: http://www.tarsnap.com/scrypt/scrypt.pdf</span>\n <span class=\"hljs-comment\">// scrypt.Defaults (N=16384, r=8, p=1) makes it easy to provide these parameters, and</span>\n <span class=\"hljs-comment\">// (should you wish) provide your own values via the scrypt.Params type.</span>\n hash, err := scrypt.GenerateFromPassword([]<span class=\"hljs-keyword\">byte</span>(passwordFromForm), scrypt.DefaultParams)\n <span class=\"hljs-keyword\">if</span> err != <span class=\"hljs-literal\">nil</span> {\n log.Fatal(err)\n }\n\n <span class=\"hljs-comment\">// Print the derived key with its parameters prepended.</span>\n fmt.Printf(<span class=\"hljs-string\">"%s\\n"</span>, hash)\n\n <span class=\"hljs-comment\">// Uses the parameters from the existing derived key. Return an error if they don't match.</span>\n err := scrypt.CompareHashAndPassword(hash, []<span class=\"hljs-keyword\">byte</span>(passwordFromForm))\n <span class=\"hljs-keyword\">if</span> err != <span class=\"hljs-literal\">nil</span> {\n log.Fatal(err)\n }\n}</pre><h2>Upgrading Parameters</h2>\n<p>Upgrading derived keys from a set of parameters to a "stronger" set of parameters\nas hardware improves, or as you scale (and move your auth process to separate\nhardware), can be pretty useful. Here's how to do it with simple-scrypt:</p>\n<pre><span class=\"hljs-function\"><span class=\"hljs-keyword\">func</span> <span class=\"hljs-title\">main</span><span class=\"hljs-params\">()</span></span> {\n <span class=\"hljs-comment\">// SCENE: We've successfully authenticated a user, compared their submitted</span>\n <span class=\"hljs-comment\">// (cleartext) password against the derived key stored in our database, and</span>\n <span class=\"hljs-comment\">// now want to upgrade the parameters (more rounds, more parallelism) to</span>\n <span class=\"hljs-comment\">// reflect some shiny new hardware we just purchased. As the user is logging</span>\n <span class=\"hljs-comment\">// in, we can retrieve the parameters used to generate their key, and if</span>\n <span class=\"hljs-comment\">// they don't match our "new" parameters, we can re-generate the key while</span>\n <span class=\"hljs-comment\">// we still have the cleartext password in memory</span>\n <span class=\"hljs-comment\">// (e.g. before the HTTP request ends).</span>\n current, err := scrypt.Cost(hash)\n <span class=\"hljs-keLine truncated
|
||||
},
|
||||
{
|
||||
"component": "footer",
|
||||
"links": [
|
||||
{
|
||||
"href": "https://github.com/elithrar/simple-scrypt",
|
||||
"text": "GitHub"
|
||||
},
|
||||
{
|
||||
"href": "https://github.com/elithrar",
|
||||
"text": "elithrar"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
+1
-1
@@ -260,7 +260,7 @@ func Calibrate(timeout time.Duration, memMiBytes int, params Params) (Params, er
|
||||
var again bool
|
||||
memBytes := memMiBytes << 20
|
||||
// If we'd use more memory then the allowed, we can tune the memory usage
|
||||
for 128*p.R*p.N > memBytes {
|
||||
for 128*int64(p.R)*int64(p.N) > int64(memBytes) {
|
||||
if p.R > 1 {
|
||||
// by lowering r
|
||||
p.R--
|
||||
|
||||
+2
-2
@@ -23,11 +23,11 @@ var testParams = []struct {
|
||||
{true, Params{1048576, 8, 2, 64, 128}},
|
||||
{false, Params{-1, 8, 1, 16, 32}}, // invalid N
|
||||
{false, Params{0, 8, 1, 16, 32}}, // invalid N
|
||||
{false, Params{1 << 31, 8, 1, 16, 32}}, // invalid N
|
||||
{false, Params{1<<31 - 1, 8, 1, 16, 32}}, // invalid N
|
||||
{false, Params{16384, 0, 12, 16, 32}}, // invalid R
|
||||
{false, Params{16384, 8, 0, 16, 32}}, // invalid R > maxInt/128/P
|
||||
{false, Params{16384, 1 << 24, 1, 16, 32}}, // invalid R > maxInt/256
|
||||
{false, Params{1 << 31, 8, 0, 16, 32}}, // invalid p < 0
|
||||
{false, Params{1<<31 - 1, 8, 0, 16, 32}}, // invalid p < 0
|
||||
{false, Params{4096, 8, 1, 5, 32}}, // invalid SaltLen
|
||||
{false, Params{4096, 8, 1, 16, 2}}, // invalid DKLen
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user