pwstore-fast 2.4.1 → 2.4.2
raw patch · 2 files changed
+16/−7 lines, 2 filesdep +byteabledep −SHA
Dependencies added: byteable
Dependencies removed: SHA
Files
- Crypto/PasswordStore.hs +13/−4
- pwstore-fast.cabal +3/−3
Crypto/PasswordStore.hs view
@@ -103,6 +103,7 @@ ) where +import qualified Crypto.Hash as CH import qualified Crypto.Hash.SHA256 as H import qualified Data.ByteString.Char8 as B import qualified Data.ByteString as BS@@ -110,8 +111,8 @@ import qualified Data.Binary as Binary import Control.Monad import Control.Monad.ST+import Data.Byteable (toBytes) import Data.STRef-import qualified Data.Digest.Pure.SHA as SHA import Data.Bits import Data.ByteString.Char8 (ByteString) import Data.ByteString.Base64 (encode, decodeLenient)@@ -119,6 +120,9 @@ import System.Random import Data.Maybe import qualified Control.Exception+import Data.Char+import Data.List+import Data.Function --------------------- -- Cryptographic base@@ -150,8 +154,7 @@ -> ByteString -- ^ The encoded message hmacSHA256 secret msg =- let digest = SHA.hmacSha256 (fromStrict secret) (fromStrict msg)- in toStrict . SHA.bytestringDigest $ digest+ toBytes (CH.hmacGetDigest (CH.hmac secret msg) :: CH.Digest CH.SHA256) -- | PBKDF2 key-derivation function. -- For details see @http://tools.ietf.org/html/rfc2898@.@@ -296,6 +299,12 @@ makePasswordSalt :: ByteString -> Salt -> Int -> ByteString makePasswordSalt = makePasswordSaltWith pbkdf1 (2^) +-- | Constant-time comparison function to use instead of == when comparing with a secret+constantTimeCompare a b = + ((==) `on` length) a b && 0 == (foldl1 (.|.) joined)+ where+ joined = zipWith (xor `on` ord) a b+ -- | 'verifyPasswordWith' @algorithm userInput pwHash@ verifies -- the password @userInput@ given by the user against the stored password -- hash @pwHash@, with the hashing algorithm @algorithm@. Returns 'True' if the@@ -322,7 +331,7 @@ case readPwHash pwHash of Nothing -> False Just (strength, salt, goodHash) ->- encode (algorithm userInput salt (strengthModifier strength)) == goodHash+ encode (algorithm userInput salt (strengthModifier strength)) `constantTimeCompare` goodHash -- | Like 'verifyPasswordWith', but uses 'pbkdf1' as algorithm. verifyPassword :: ByteString -> ByteString -> Bool
pwstore-fast.cabal view
@@ -1,5 +1,5 @@ Name: pwstore-fast-Version: 2.4.1+Version: 2.4.2 Synopsis: Secure password storage. Description: To store passwords securely, they should be salted, then hashed with a slow hash function. This library@@ -30,7 +30,7 @@ Build-depends: base >= 4, base < 5, bytestring >= 0.9, base64-bytestring >= 0.1, binary >= 0.5,- SHA >= 1.6.1,- cryptohash >= 0.6, random >= 1+ cryptohash >= 0.6, random >= 1,+ byteable >= 0.1 ghc-options: -Wall