pub struct Argon2 {
pub m_cost: u32,
pub t_cost: u32,
pub p_cost: u32,
pub hash_length: u32,
pub algorithm: Algorithm,
pub version: Version,
}Expand description
Argon2 instance
§Parameters
m_cost- The memory cost in kibibytest_cost- Iteration costp_cost- Parallelizationhash_length- The length of the hash in bytesalgorithm- The algorithm to useversion- The version of the algorithm to use
By default it will use Argon2id, version 0x13 and a 64 byte hash length.
It is not recommended to change these specific values, they are fine for most use cases.
Generally speaking you don’t want to mess with the t_cost and p_cost parameters a lot.
§About the m_cost, t_cost and p_cost parameters
§m_cost
You should mostly adjust the m_cost if you really want to increase the security of the hash since this is
the major bottleneck for GPUs and ASICs.
Anything from 1024_000 and beyond is considered very secure, if you are paranoid you should increase it
to the max physical RAM of the machine this hash will be computed on.
§t_cost
For most use cases a good value is between 8 and 30.
Increasing the t_cost will increase the time it takes to compute the hash linearly.
For example if the hash takes 10 seconds to compute with t_cost set to 8 and you increase it to 16 it will take roughly twice the time.
§p_cost
The degree of parallelism (number of lanes and threads). It does not change the total amount of work — it only decides how many lanes that work is spread over, so it shortens the wall-clock time only when the machine has spare cores to run those lanes on.
For example if the hash takes 10 seconds to compute with p_cost set to 1 and you increase it to 2
it will take roughly half the time, provided a second core is free; on a single-core machine it will not get faster.
Keep in mind increasing the p_cost beyond the machine’s physical cores will not increase the speed of the hash computation
but in case of a brute-force attack the attacker will be able to use more cores to compute the hash and thus giving him leverage.
For that reason p_cost is kept at 1.
§Presets
There are some presets for the Argon2 struct that you can use.
Argon2::very_fast()Argon2::fast()Argon2::balanced()Argon2::slow()Argon2::very_slow()
Fields§
§m_cost: u32§t_cost: u32§p_cost: u32§hash_length: u32The length of the hash in bytes.
Must be at least 4 (ARGON2_MIN_OUTLEN) the C library accepts anything up to
u32::MAX (ARGON2_MAX_OUTLEN), so the type itself is the upper bound.
algorithm: AlgorithmBy default we use the Argon2id
version: VersionBy default we use the version 0x13
Implementations§
Source§impl Argon2
impl Argon2
Sourcepub fn new(m_cost: u32, t_cost: u32, p_cost: u32) -> Argon2
pub fn new(m_cost: u32, t_cost: u32, p_cost: u32) -> Argon2
Create a new Argon2 instance with the given parameters.
By default it will use the Argon2id with a 64 byte hash length.
§Arguments
m_cost- The memory cost in kibibytest_cost- Iteration costp_cost- Parallelization
pub fn with_algorithm(self, algorithm: Algorithm) -> Argon2
pub fn with_version(self, version: Version) -> Argon2
Sourcepub fn with_hash_length(self, hash_length: u32) -> Argon2
pub fn with_hash_length(self, hash_length: u32) -> Argon2
Sets the hash length in bytes.
Values below 4 (ARGON2_MIN_OUTLEN) are rejected by Argon2::hash_password with
Argon2Error::OutputTooShort.
Sourcepub fn hash_password(
&self,
password: &str,
salt: Vec<u8>,
) -> Result<Vec<u8>, Argon2Error>
pub fn hash_password( &self, password: &str, salt: Vec<u8>, ) -> Result<Vec<u8>, Argon2Error>
Sourcepub fn encode(&self) -> Vec<u8> ⓘ
pub fn encode(&self) -> Vec<u8> ⓘ
Encodes the Argon2 configuration into a byte vector using little-endian byte order.
hash_length is written as an 8-byte field, so the encoded form is still 28 bytes long.
Sourcepub fn decode(data: &[u8]) -> Result<Argon2, Argon2Error>
pub fn decode(data: &[u8]) -> Result<Argon2, Argon2Error>
Decodes the Argon2 configuration from a byte slice using little-endian byte order.
§Errors
Returns Error::Argon2(Argon2Error::DecodingFail) if the data is too short, contains
invalid enum values, or holds a hash_length that does not fit in a u32.
Trait Implementations§
Source§impl Default for Argon2
impl Default for Argon2
Source§fn default() -> Argon2
fn default() -> Argon2
The Argon2::very_fast preset: Argon2id, version 0x13, a 64 byte hash length and
a 128_000 KiB (128 MiB) memory cost.
A configuration with every cost set to 0 can never hash anything, so Default is a set
of parameters that actually works, kept cheap enough to use without tuning.
This must stay a struct literal: every preset below (and Argon2::new) fills its
remaining fields with ..Default::default(), so delegating to a preset here would
recurse forever.