Golang/App Engine - securely hashing a user's password

被刻印的时光 ゝ 提交于 2019-11-30 05:10:05

Have a look at go.crypto. It offers support for pbkdf2 and bcrypt. Both implementations are purely written in Go and should work on GAE just fine.

The most simple to use is probably bcrypt. To get the package run:

go get golang.org/x/crypto/bcrypt

Example usage:

import "golang.org/x/crypto/bcrypt" 

func clear(b []byte) {
    for i := 0; i < len(b); i++ {
        b[i] = 0;

func Crypt(password []byte) ([]byte, error) {
    defer clear(password)
    return bcrypt.GenerateFromPassword(password, bcrypt.DefaultCost)

ctext, err := Crypt(pass)

if err != nil {


The output will be something like this:


If you want simply the hash, use pbkdf2. Example:

import "golang.org/x/crypto/pbkdf2"

func HashPassword(password, salt []byte) []byte {
    defer clear(password)
    return pbkdf2.Key(password, salt, 4096, sha256.Size, sha256.New)

pass := []byte("foo")
salt := []byte("bar")

fmt.Printf("%x\n", HashPassword(pass, salt))