Branch :
| Author | Commit | Date | CI | Message |
|---|---|---|---|---|
| 280d0daa | 2022-08-26 20:51:13 | update to py3-bcrypt-4.0.0 | ||
| abb59a48 | 2022-05-03 07:57:42 | update to py3-bcrypt-3.2.2 | ||
| 8c0294c2 | 2022-03-11 19:53:16 | drop RCS Ids | ||
| 92663917 | 2021-09-08 07:19:52 | now that py-paramiko is py3-only, we can update py-bcrypt to 3.2.0 which no longer supports py2. | ||
| df1da998 | 2018-02-27 21:47:38 | remove traces of utf8 encoding in pkg/DESCR bump accordingly | ||
| d7f04798 | 2016-10-29 18:25:56 | Unbreak after py-setuptools update. This makes use of MODPY_ABI_TAG ok sthen@ | ||
| 7d162589 | 2016-07-01 15:28:44 | update to py-bcrypt-3.1.0 | ||
| d82ed592 | 2016-01-15 12:34:14 | update to py-bcrypt-2.0.0 (maybe a different codebase or fork; anyway it supports $2b$ which the in-tree version doesn't) and take maintainer | ||
| e99b9c36 | 2014-03-19 11:15:56 | SECURITY update to py-bcrypt 0.4, from Francisco de Borja Lopez Rio - while there, fix WANTLIB and enable python 3 support; by me Fix concurrency bug reported by Alan Fairless of spideroak.com: Multiple threads may hash into the same memory area simultaneously. This may manifest as occasional random authentication failures (as user-a's password hash is compared to user-b's), but could potentially be used to bypass password checking by an attacker (user-a attempts login on user-b's account, while simultaneously flooding auth requests against user-a's account to overwrite the hash). | ||
| e2954dfa | 2013-03-26 21:37:26 | import ports/security/py-bcrypt, ok benoit@ py-bcrypt is a Python wrapper of OpenBSD's Blowfish password hashing code, as described in "A Future-Adaptable Password Scheme" by Niels Provos and David Mazières. This system hashes passwords using a version of Bruce Schneier's Blowfish block cipher with modifications designed to raise the cost of off-line password cracking and frustrate fast hardware implementation. The computation cost of the algorithm is parametised, so it can be increased as computers get faster. The intent is to make a compromise of a password database less likely to result in an attacker gaining knowledge of the plaintext passwords (e.g. using John the Ripper). |