Sitelet https://web.archive.org/web/20201202084120/https://github.com/verdaccio/verdaccio/issues/1917
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow other password hashing algorithms #1917

Open
juanpicado opened this issue Mar 24, 2019 · 6 comments
Open

Allow other password hashing algorithms #1917

juanpicado opened this issue Mar 24, 2019 · 6 comments

Comments

@juanpicado
Copy link
Member

@juanpicado juanpicado commented Mar 24, 2019

My reason:

Currently, we support verify on multiple formats but we do not on the sign the password, we shoud allow this plugin to sign with something different than CRYPT

https://httpd.apache.org/docs/2.4/misc/password_encryptions.html

Additional information:

@pelallemant
Copy link

@pelallemant pelallemant commented Mar 24, 2019 •

In config.yaml, an option encryption could be added in auth > htpasswd with several choices.
By default, a secured one would be expected, making a new verdaccio node safe for the user registering with npm adduser.

@juanpicado juanpicado pinned this issue Mar 25, 2019
@juanpicado juanpicado transferred this issue from verdaccio/verdaccio-htpasswd Jul 24, 2019
@DanielRuf DanielRuf changed the title Allow other password encryptions Allow other password hashing algorithms Apr 27, 2020
@DanielRuf
Copy link
Member

@DanielRuf DanielRuf commented Apr 27, 2020

Currently, we support verify on multiple formats but we do not on the sign the password, we shoud allow this plugin to sign with something different than CRYPT

To clarify this, we do not sign but hash using crypt-DES.
Signed messages with hashing would be HMAC algorithms like HMAC-SHA256. But this is not recommended for passwords.

https://security.stackexchange.com/questions/3165/hmac-why-not-hmac-for-password-storage

Instead we should target bcrypt, scrypt (sodium) and so on.

So the option should be something like hashing_algorithm.

scrypt is in Node since 10.5, see https://nodejs.org/api/crypto.html#crypto_crypto_scrypt_password_salt_keylen_options_callback

For others we have to check if we can use node-forge, crypto-js and / or bcrypt.

@DanielRuf
Copy link
Member

@DanielRuf DanielRuf commented Apr 27, 2020

Additionally the SHA-3 winner (Keccak) could be an option too (if some need it) available as sha3 and keccak.

But we should prefer bcrypt and scrypt. For both we can set the rounds / interations and so the hashing_algorithm should support further settings like the rounds / iterations and other input variables.

See https://gchq.github.io/CyberChef/?op=Bcrypt and https://gchq.github.io/CyberChef/?op=Scrypt

@juanpicado
Copy link
Member Author

@juanpicado juanpicado commented Apr 28, 2020

An example of plugin bcrypt using https://github.com/idangozlan/verdaccio-bitbucket

@juanpicado juanpicado transferred this issue from verdaccio/monorepo Aug 26, 2020
@juanpicado juanpicado added this to the 5.x.x milestone Sep 23, 2020
@piraz
Copy link

@piraz piraz commented Sep 24, 2020

What a coincidence I'm working on the same issue on some of my projects. I don't have full knowledge about what you do to fix the issue but I just bump to those articles:

This one is for strengthening ldap passwords using linux crypt: https://www.redpill-linpro.com/techblog/2016/08/16/ldap-password-hash.html. I don't even know that crypt would generate passwords in another formats, so on ldap you generate a SHA512, SHA256 or Blowfish and stored it the hash signaled as crypt and ldap will use the lib with that strong algo pointed in the hash.

This one is about peper and how to validate the generated hash: https://crackstation.net/hashing-security.htm. In the case of pepper that must be considered well as old passwords are not peppered so you have a compatibility issue that should be solved in your system before.

On my projects I can get direct interface to unix cyrpt but I don't know if there is anything available in JavaScript.

I hope that could be useful information on this task.

@juanpicado
Copy link
Member Author

@juanpicado juanpicado commented Sep 24, 2020

Thanks @piraz really appreciated 👏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Verdaccio 5
  
To do
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
4 participants
You can’t perform that action at this time.