refactor(security): upgrade password hashing algorithm #69
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
We currently use a
bcrypt
has implementation for hashing passwords and the like.bcrypt
is efficient, yet security could be improved if theargon2
hashing would be used. Downside is thatargon2
burns more CPU on the server, which could affect performance.This issue is to track and discuss considerations in upgrading the hashing approach.