refactor(security): upgrade password hashing algorithm #69
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
We currently use a
bcrypthas implementation for hashing passwords and the like.bcryptis efficient, yet security could be improved if theargon2hashing would be used. Downside is thatargon2burns more CPU on the server, which could affect performance.This issue is to track and discuss considerations in upgrading the hashing approach.