docs: insecure example
オープン
documentation
- 主要言語
- TypeScript
- スター
- 3.5k
- フォーク
- 173
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
The current Quick Start guide shows an example where a password is hashed using SHA-256 - https://threads.js.org/getting-started
This is not a secure example, and may lead readers without a meter for secure code to copy-paste the example.
- SHA-256 is a *fast* cryptographic hash, and not a key derivation function (like bcrypt or scrypt)
- This means it is NOT suited to "hashing" passwords
_I would suggest using another example entirely that doesn't rely on password hashing_, but if you **must** use it, use the PBKDF2 algorithm from SubtleCrypto to derive a key from the user input, with sufficient rounds.
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。