SimpleHashing.Net
2.0.0
See the version list below for details.
dotnet add package SimpleHashing.Net --version 2.0.0
NuGet\Install-Package SimpleHashing.Net -Version 2.0.0
<PackageReference Include="SimpleHashing.Net" Version="2.0.0" />
paket add SimpleHashing.Net --version 2.0.0
#r "nuget: SimpleHashing.Net, 2.0.0"
// Install SimpleHashing.Net as a Cake Addin #addin nuget:?package=SimpleHashing.Net&version=2.0.0 // Install SimpleHashing.Net as a Cake Tool #tool nuget:?package=SimpleHashing.Net&version=2.0.0
SimpleHashing.Net
This is a simple wrapper on top of Microsoft PBKDF2 implementation to store and verify password hashes. It works very similar to bcrypt (not from the point of view of cryptography, but it generates a similar type of string that can be saved to database and used for verification later).
Nuget
Nuget package is available here: https://www.nuget.org/packages/SimpleHashing.Net/
Usage example
ISimpleHash simpleHash = new SimpleHash();
// Creating a user hash, hashedPassword can be stored in a database
// hashedPassword contains the number of iterations and salt inside it similar to bcrypt format
string hashedPassword = simpleHash.Compute("Password123");
// Validating user's password by first loading it from database by username
string storedHash = _repository.GetUserPasswordHash(username);
bool isPasswordValid = false;
if (storedHash != null)
{
isPasswordValid = simpleHash.Verify("Password123", storedHash);
}
Security
SimpleHashing.Net does not do any self-made cryptography, but it is based on Microsoft implementation of PBKDF2 via the class Rfc2898DeriveBytes. The problem with this class is that it's not very convenient to use, so this simple wrapper allows an easy integration with solutions that need to store/verify password with strong cryptography. Simplicity was the main focus, so some parameters are hard-coded:
- Salt size is 16 bytes (128 bits)
- HashSize is 32 bytes (256 bits)
- Default iterations count is 50000
Iteration parameter can be passed to the Compute method to override the default settings. Rough estimate for execution time on few years old machine is 0.5 seconds. To increase security against brute force attacks this parameter can be increased to a desired value. For more information on number of iterations you can read an excellent stackexchange answer by Thomas Pornin.
You can use Estimate method to check how long it will take to compute the hash string.
Product | Versions Compatible and additional computed target framework versions. |
---|---|
.NET | net5.0 was computed. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 was computed. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. |
.NET Core | netcoreapp2.0 was computed. netcoreapp2.1 was computed. netcoreapp2.2 was computed. netcoreapp3.0 was computed. netcoreapp3.1 was computed. |
.NET Standard | netstandard2.0 is compatible. netstandard2.1 was computed. |
.NET Framework | net461 was computed. net462 was computed. net463 was computed. net47 was computed. net471 was computed. net472 was computed. net48 was computed. net481 was computed. |
MonoAndroid | monoandroid was computed. |
MonoMac | monomac was computed. |
MonoTouch | monotouch was computed. |
Tizen | tizen40 was computed. tizen60 was computed. |
Xamarin.iOS | xamarinios was computed. |
Xamarin.Mac | xamarinmac was computed. |
Xamarin.TVOS | xamarintvos was computed. |
Xamarin.WatchOS | xamarinwatchos was computed. |
-
.NETStandard 2.0
- No dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
Target framework is changed to netstandard 2.0