autocert
nacl
autocert | nacl | |
---|---|---|
10 | 1 | |
2,941 | 540 | |
0.6% | - | |
8.1 | 0.0 | |
8 days ago | over 1 year ago | |
Go | Go | |
BSD 3-clause "New" or "Revised" License | BSD 3-clause "New" or "Revised" License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
autocert
-
Current bcrypt is problematic I find. Made changes to core functionality. Looking for feedback
Pull request link
- GOlang ile şifreleme işlemleri için crypto paketi
- Argon2 or Argon2id still recommended over Bcrypt for Password Hashing?
-
SHA-3 Buffer Overflow
The version in the Golang stdlib is a pure-go implementation, but there's an assembler variant optimized for amd64 (https://github.com/golang/crypto/blob/master/sha3/keccakf_am...), which is apparently derived from the XKCP package.
Bad news for the (mostly-Golang) Ethereum ecosystem...
-
Web dev learning path advice
Learn crypto library and how to encrypt and hash: https://github.com/golang/crypto
-
Hashing password
In last section we have created users table in our database, but we are currently storing user's password in plain text. This is something we should never do, and instead we need to store hashed password with random salt. For that we will use golang/crypto library. First we need to expand our User structure:
- Minio Changes License to AGPL
-
SIEC elliptic curve vs other better known ones ?
So in conclusion, croc seems to be pretty secure as long as you use P-256 (or P-384). Internally, the standard golang.org/x/crypto library is used, which I can guarantee is very secure, as it is used in millions of web servers around the world, and Go is a language maintained by Google, which has many security professionals at their disposal. Ultimately, the decision is yours. While I can give you my opinion and point you to correct documents, you should trust nobody other than yourself. Not even me. But still, I recommend P-256 above everything else.
-
Crowdsourcing for healthcare tool accepting DOGE as payment feedback
I've been considering developing suck tools with Golang. Golang's crypto package golang crypto might be a great starting point if your familiar with language.
-
how does bcrypt.CompareHash function know which cost to select?
https://github.com/golang/crypto/blob/eec23a3978adcfd26c29f4153eaa3e3d9b2cc53a/bcrypt/bcrypt.go#L234-L254
nacl
-
Ten years of experience, still failing phone screens
Your post ought to be ample proof that subjective opinions (like the one you display here) are not solid grounds for hiring decisions.
When looking at this person's github repo, I -unlike you- see a vast number of trivial projects that can best be described as regurgitations of other people's projects. Even worse, if you actually look at his first pinned project (https://github.com/kevinburke/nacl), you'll see that it is nothing but a wrapper with trivial changes/updates.
TL;DR I see a lot of projects that can provide the illusion of competence but, when actually inspected, telling me not to hire this person.
What are some alternatives?
lego - Let's Encrypt/ACME client and library written in Go
bitwarden-go - A Bitwarden-compatible server written in Golang
ACL - A simple but powerful Access Control List manager
Themis - Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14 platforms.
simple-scrypt - A convenience library for generating, comparing and inspecting password hashes using the scrypt KDF in Go 🔑
certmagic - Automatic HTTPS for any Go program: fully-managed TLS certificate issuance and renewal
acmetool - :lock: acmetool, an automatic certificate acquisition tool for ACME (Let's Encrypt)
BadActor - BadActor.org An in-memory application driven jailer written in Go
Go random string generator - Flexible and customizable random string generator