9 releases (breaking)

✓ Uses Rust 2018 edition

new 0.7.0 Jan 21, 2020
0.6.1 Dec 26, 2019
0.6.0 Nov 18, 2019
0.5.1 Aug 15, 2019
0.1.0 Mar 2, 2017

#17 in Cryptography

Download history 15542/week @ 2019-10-12 14960/week @ 2019-10-19 15791/week @ 2019-10-26 16526/week @ 2019-11-02 17882/week @ 2019-11-09 18804/week @ 2019-11-16 19450/week @ 2019-11-23 20420/week @ 2019-11-30 20685/week @ 2019-12-07 20555/week @ 2019-12-14 10293/week @ 2019-12-21 12339/week @ 2019-12-28 24049/week @ 2020-01-04 23665/week @ 2020-01-11 29082/week @ 2020-01-18 1200/week @ 2020-01-25

79,155 downloads per month
Used in 1,708 crates (16 directly)

MIT/Apache

89KB
1.5K SLoC

Rust-argon2

Rust library for hashing passwords using Argon2, the password-hashing function that won the Password Hashing Competition (PHC).

Usage

To use rust-argon2, add the following to your Cargo.toml:

[dependencies]
rust-argon2 = "0.7"

And the following to your crate root:

extern crate argon2;

Examples

Create a password hash using the defaults and verify it:

use argon2::{self, Config};

let password = b"password";
let salt = b"randomsalt";
let config = Config::default();
let hash = argon2::hash_encoded(password, salt, &config).unwrap();
let matches = argon2::verify_encoded(&hash, password).unwrap();
assert!(matches);

Create a password hash with custom settings and verify it:

use argon2::{self, Config, ThreadMode, Variant, Version};

let password = b"password";
let salt = b"othersalt";
let config = Config {
    variant: Variant::Argon2i,
    version: Version::Version13,
    mem_cost: 65536,
    time_cost: 10,
    lanes: 4,
    thread_mode: ThreadMode::Parallel,
    secret: &[],
    ad: &[],
    hash_length: 32
};
let hash = argon2::hash_encoded(password, salt, &config).unwrap();
let matches = argon2::verify_encoded(&hash, password).unwrap();
assert!(matches);

Limitations

This crate has the same limitation as the blake2-rfc crate that it uses. It does not attempt to clear potentially sensitive data from its work memory. To do so correctly without a heavy performance penalty would require help from the compiler. It's better to not attempt to do so than to present a false assurance.

This version uses the standard implementation and does not yet implement optimizations. Therefore, it is not the fastest implementation available.

License

Rust-argon2 is dual licensed under the MIT and Apache 2.0 licenses, the same licenses as the Rust compiler.

Contributions

Contributions are welcome. By submitting a pull request you are agreeing to make you work available under the license terms of the Rust-argon2 project.

Dependencies

~470KB