IABSD.fr/ports/security/py-bcrypt/pkg

Branch :


Log

Author Commit Date CI Message
280d0daa 2022-08-26 20:51:13 update to py3-bcrypt-4.0.0
abb59a48 2022-05-03 07:57:42 update to py3-bcrypt-3.2.2
8c0294c2 2022-03-11 19:53:16 drop RCS Ids
92663917 2021-09-08 07:19:52 now that py-paramiko is py3-only, we can update py-bcrypt to 3.2.0 which no longer supports py2.
df1da998 2018-02-27 21:47:38 remove traces of utf8 encoding in pkg/DESCR bump accordingly
d7f04798 2016-10-29 18:25:56 Unbreak after py-setuptools update. This makes use of MODPY_ABI_TAG ok sthen@
7d162589 2016-07-01 15:28:44 update to py-bcrypt-3.1.0
d82ed592 2016-01-15 12:34:14 update to py-bcrypt-2.0.0 (maybe a different codebase or fork; anyway it supports $2b$ which the in-tree version doesn't) and take maintainer
e99b9c36 2014-03-19 11:15:56 SECURITY update to py-bcrypt 0.4, from Francisco de Borja Lopez Rio - while there, fix WANTLIB and enable python 3 support; by me Fix concurrency bug reported by Alan Fairless of spideroak.com: Multiple threads may hash into the same memory area simultaneously. This may manifest as occasional random authentication failures (as user-a's password hash is compared to user-b's), but could potentially be used to bypass password checking by an attacker (user-a attempts login on user-b's account, while simultaneously flooding auth requests against user-a's account to overwrite the hash).
e2954dfa 2013-03-26 21:37:26 import ports/security/py-bcrypt, ok benoit@ py-bcrypt is a Python wrapper of OpenBSD's Blowfish password hashing code, as described in "A Future-Adaptable Password Scheme" by Niels Provos and David Mazières. This system hashes passwords using a version of Bruce Schneier's Blowfish block cipher with modifications designed to raise the cost of off-line password cracking and frustrate fast hardware implementation. The computation cost of the algorithm is parametised, so it can be increased as computers get faster. The intent is to make a compromise of a password database less likely to result in an attacker gaining knowledge of the plaintext passwords (e.g. using John the Ripper).