rspec/rules/S5344/python/message.adoc

12 lines
400 B
Plaintext

=== Message
For hashlib:
* For scrypt: "Use strong scrypt parameters"
* For pbkdf2_hmac: "Use at least ``+{min_iterations}+`` PBKDF2 iterations"
** If `hash_name` is `"sha1"`, then min_iterations is 1300000
** If `hash_name` is `"sha256"`, then min_iterations is 600000
** If `hash_name` is `"sha512"`, then min_iterations is 210000
For Django: "Use a secure hashing algorithm to store passwords"