sec-bcrypt-scrypt-hashing
The file ~/sec_bcrypt_scrypt_hashing.py implements a comprehensive password hashing comparison with five approaches, a rainbow table attack demo, and performance benchmarks.
1. Naive SHA256 — hashlib.sha256(password.encode()).hexdigest() — no salt, deterministic, trivially rainbow-table-attackable.
2. Salted SHA256 — hashlib.sha256(salt + password).hexdigest() — random 16-byte salt per call, defeats rainbow tables, but still fast (~1 µs) so vulnerable to brute-force.
3. bcrypt — using bcrypt.hashpw() with configurable cost factor (4-14). Slower by design (0.8 ms at cost=4, ~790 ms at cost=14). Built-in salt, self-contained hash string.
4. scrypt — using hashlib.scrypt() with memory-hard parameters (N, r, p). Configurable memory/CPU tradeoff. ~32 ms at N=16384.
5. Argon2id — using argon2-cffi with configurable time cost, memory cost, and parallelism. ~17 ms at t=2, m=19MiB.
All 13 verification tests pass: | Test | Result | |------|--------| | Naive SHA256 consistency | ✓ | | Salted SHA256 uniqueness per call | ✓ | | Salted SHA256 deterministic with fixed salt | ✓ | | bcrypt hash/verify round-trip | ✓ | | bcrypt produces different hash each call | ✓ | | scrypt hash/verify round-trip | ✓ | | scrypt uniqueness per call | ✓ | | scrypt constant-time comparison | ✓ | | argon2 hash/verify round-trip | ✓ | | argon2 uniqueness per call | ✓ | | Empty string handling | ✓ | | Unicode/multi-byte password handling | ✓ | | 1000-char password (bcrypt 72B limit documented) | ✓ | **Performance benchmarks:** - SHA256 (naive/salted): **~1 µs** — blazing fast, bad for passwords - bcrypt (cost=4): **0.8 ms** — 800× slower than SHA256 - bcrypt (cost=10): **49 ms** — default recommended - bcrypt (cost=14): **788 ms** — paranoid level - scrypt (N=16384): **32 ms** — memory-hard - argon2id (t=2, m=19MiB): **17 ms** — modern winner **Rainbow table demo:** "password" and "monkey" cracked from unsalted SHA256 in under 2 µs each. All salted/adaptive hashes **immune**. ---
{"model": "claude", "problem_class": "sec-bcrypt-scrypt-hashing", "result": "passed", "tests": 13}The file ~/sec_bcrypt_scrypt_hashing.py implements a comprehensive password hashing comparison with five approaches, a rainbow table attack demo, and performance benchmarks.
1. Naive SHA256 — hashlib.sha256(password.encode()).hexdigest() — no salt, deterministic, trivially rainbow-table-attackable.
2. Salted SHA256 — hashlib.sha256(salt + password).hexdigest() — random 16-byte salt per call, defeats rainbow tables, but still fast (~1 µs) so vulnerable to brute-force.
3. bcrypt — using bcrypt.hashpw() with configurable cost factor (4-14). Slower by design (0.8 ms at cost=4, ~790 ms at cost=14). Built-in salt, self-contained hash string.
4. scrypt — using hashlib.scrypt() with memory-hard parameters (N, r, p). Configurable memory/CPU tradeoff. ~32 ms at N=16384.
5. Argon2id — using argon2-cffi with configurable time cost, memory cost, and parallelism. ~17 ms at t=2, m=19MiB.
All 13 verification tests pass: | Test | Result | |------|--------| | Naive SHA256 consistency | ✓ | | Salted SHA256 uniqueness per call | ✓ | | Salted SHA256 deterministic with fixed salt | ✓ | | bcrypt hash/verify round-trip | ✓ | | bcrypt produces different hash each call | ✓ | | scrypt hash/verify round-trip | ✓ | | scrypt uniqueness per call | ✓ | | scrypt constant-time comparison | ✓ | | argon2 hash/verify round-trip | ✓ | | argon2 uniqueness per call | ✓ | | Empty string handling | ✓ | | Unicode/multi-byte password handling | ✓ | | 1000-char password (bcrypt 72B limit documented) | ✓ | **Performance benchmarks:** - SHA256 (naive/salted): **~1 µs** — blazing fast, bad for passwords - bcrypt (cost=4): **0.8 ms** — 800× slower than SHA256 - bcrypt (cost=10): **49 ms** — default recommended - bcrypt (cost=14): **788 ms** — paranoid level - scrypt (N=16384): **32 ms** — memory-hard - argon2id (t=2, m=19MiB): **17 ms** — modern winner **Rainbow table demo:** "password" and "monkey" cracked from unsalted SHA256 in under 2 µs each. All salted/adaptive hashes **immune**. ---
{"model": "claude", "problem_class": "sec-bcrypt-scrypt-hashing", "result": "passed", "tests": 13}