hedgedoc/backend/src/utils
Erik Michelson f30f0d8e51 fix(passwords): use argon2id instead of bcrypt
OWASP [1] recommends for password hashing the following algorithms in
descending order: argon2id, scrypt, bcrypt. They state that bcrypt may
be used in legacy systems or when required due to legal regulations.
We're however not building any legacy application. Even HedgeDoc 1.x
utilizes a more modern algorithm by using scrypt.

While bcrypt is not insecure per se, our implementation had a major
security flaw, leading to invalid passwords being accepted in certain
cases. The bcrypt nodejs package - and the OWASP cheatsheet as well -
point out, that the maximum input length of passwords is limited to 72
bytes with bcrypt. When some user has a password longer than 72 bytes in
use, only the first 72 bytes are required to log in successfully.
Depending on the encoding (which could be UTF-8 or UTF-16 depending on
different circumstances) this could in worst-case be at 36 characters,
which is not very unusual for a password. See also [2].

This commit changes the used algorithm to argon2id. Argon2id has been in
use for several years now and seems to be a well-designed password
hashing function that even won the 2015 Password Hashing Competition.
Argon2 does not have any real-world max input length for passwords (it
is at 4 GiB).

The node-rs/argon2 implementation seems to be well maintained, widely
used (more than 150k downloads per week) and is published with
provenance, proving that the npm package was built on GitHub actions
using the source code in the repository. The implementation is written
in Rust, so it should be safe against memory leakages etc.

[1]: https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Che
     at_Sheet.html#password-hashing-algorithms
[2]: https://security.stackexchange.com/a/39851

Signed-off-by: Erik Michelson <github@erik.michelson.eu>
2024-08-08 20:29:23 +02:00
..
test-utils test: improve select query mock builder 2023-06-20 11:44:38 +02:00
arrayDuplicatCheck.ts fix(repository): Move backend code into subdirectory 2022-10-30 22:46:42 +01:00
base.dto..ts fix(repository): Move backend code into subdirectory 2022-10-30 22:46:42 +01:00
createSpecialGroups.ts fix(repository): Move backend code into subdirectory 2022-10-30 22:46:42 +01:00
detectTsNode.ts fix(migrations): use migration file extension according to runtime 2023-10-08 17:58:32 +02:00
password.spec.ts fix(passwords): use argon2id instead of bcrypt 2024-08-08 20:29:23 +02:00
password.ts fix(passwords): use argon2id instead of bcrypt 2024-08-08 20:29:23 +02:00
serverVersion.spec.ts fix(backend): Use regex to parse version 2023-02-05 21:21:08 +01:00
serverVersion.ts fix: support dots in semver prerelease identifier 2023-10-08 22:01:47 +02:00
session.ts fix(repository): Move backend code into subdirectory 2022-10-30 22:46:42 +01:00
setup-pipes.ts fix(repository): Move backend code into subdirectory 2022-10-30 22:46:42 +01:00
swagger.ts misc(apidocs): move URL route of API docs 2023-01-15 18:20:25 +01:00
timestamp.ts fix(repository): Move backend code into subdirectory 2022-10-30 22:46:42 +01:00
username.ts feat(backend): handle username always in lowercase 2023-06-04 21:55:19 +02:00