【发布时间】:2017-03-29 13:00:32
【问题描述】:
我尝试从文本文件中读取字符串,对其进行编码并保存到文件中。我想使用pipe 将hash 从ReadStream 转移到WriteStream。但我不知道如何转换更改后的数据。我的代码:
const crypto = require('crypto');
const fs = require('fs');
let hash = crypto.createHash('md5');
var rs = fs.createReadStream('./passwords.txt');
var ws = fs.createWriteStream('./new_passwords.txt');
rs.on('data', function(d) {
hash.update(d);
});
rs.on('end', function(d) {
console.log(hash.digest('hex'))
});
【问题讨论】:
-
不要加密密码,当攻击者得到数据库时,他也会得到加密密钥。使用随机盐在 HMAC 上迭代大约 100 毫秒,然后将盐与哈希一起保存。使用 password_hash、PBKDF2、Bcrypt 等函数和类似函数。关键是让攻击者花费大量时间通过蛮力寻找密码。
-
我第二个@zaph