Protect Your Passwords Against Dictionary Attacks

xuanbao · 2015-07-06 12:17:38 · 788 次点击    
这是一个分享于 2015-07-06 12:17:38 的资源,其中的信息可能已经有所发展或是发生改变。

I have created a package for dictionary password validation for Go.

This can be used to protect your bcrypt/scrypt/PBKDF encrypted passwords against dictionary attacks. This is much more of a threat than brute force attacks, and is of course done by checking them against a dictionary (no magic).

Motivated by Password Requirements Done Better - also called why password requirements help hackers, this package will remove all your excuses for not having good passwords.

You are able to use your own database and password dictionary. Currently the package supports importing common dictionary formats, and has built-in "drivers" for MongoDB, BoltDB, MySQL and PostgreSQL.

I have just finished up the documentation and tests, but I am very open to suggestions, and if your favorite database is missing feel free to request it.


入群交流(和以上内容无关):加入Go大咖交流群,或添加微信:liuxiaoyan-s 备注:入群;或加QQ群:692541889

788 次点击  
加入收藏 微博
暂无回复
添加一条新回复 (您需要 登录 后才能回复 没有账号 ?)
  • 请尽量让自己的回复能够对别人有帮助
  • 支持 Markdown 格式, **粗体**、~~删除线~~、`单行代码`
  • 支持 @ 本站用户;支持表情(输入 : 提示),见 Emoji cheat sheet
  • 图片支持拖拽、截图粘贴等方式上传