rspec/rules/S2257/description.adoc
2020-12-23 14:59:06 +01:00

4 lines
329 B
Plaintext

The use of a non-standard algorithm is dangerous because a determined attacker may be able to break the algorithm and compromise whatever data has been protected. Standard algorithms like ``SHA-256``, ``SHA-384``, ``SHA-512``, ... should be used instead.
This rule tracks creation of ``java.security.MessageDigest`` subclasses.