You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Mar 8, 2021. It is now read-only.
That actually seems reasonable. It wraps bouncy castle underneath, which is a respectable choice. I didn't look closely at the implementation yet, but the idea seems sound.
Friend should support HMAC in conjunction with any other credential function; obviously starting with the bcrypt that is currently shipped.
Appeals to authority include @abedra's friendly evisceration of typical Clojure webapp security practices ;-) and Mozilla's password storage guidelines.
Related work may include a "crypto-hmac" library as suggested by @weavejester here, though it looks like that was speculative?
The text was updated successfully, but these errors were encountered: