12 points BisratMelak 2 hours ago 5 comments

coppercrisp62 1 hour ago | parent

Curious where you landed on password hashing, since zero deps in Go means you either pull x/crypto for bcrypt/argon2 or hand roll scrypt from stdlib. I've been down that road and stdlib pbkdf2 wasn't there until recently.

computerfriend 1 hour ago | parent

The readme and commit messages were written by an LLM without disclosure. I didn't look at the code.

samber 1 hour ago | parent

Do you need to disclose it when everybody do it ?

[EDIT] It is disclosed in contributors

LVB 1 hour ago | parent

Nothing to see here IMO. A large amount of code piled together in a month.

The push here is “zero deps”, though at that point I might as well have Claude do it like they’ve presumable done. FWIW I’m quite ok with bringing in a well-tested/maintained dep. Hand-rolling everything down to crypto primitives like is done here isn’t an advantage.

dwroberts 1 hour ago | parent

Also, a quickly vibecoded project doing something important to security, to be used by other applications, seems like a perfect way to drop a malicious backdoor (and maybe even provides the author plausible deniability when it’s found)