4 comments

  • LVB1 hour ago
    Nothing to see here IMO. A large amount of code piled together in a month.<p>The push here is “zero deps”, though at that point I might as well have Claude do it like they’ve presumable done. FWIW I’m quite ok with bringing in a well-tested&#x2F;maintained dep. Hand-rolling everything down to crypto primitives like is done here isn’t an advantage.
    • dwroberts1 hour ago
      Also, a quickly vibecoded project doing something important to security, to be used by other applications, seems like a perfect way to drop a malicious backdoor (and maybe even provides the author plausible deniability when it’s found)
    • natty9828233 minutes ago
      [flagged]
  • BisratMelak2 hours ago
    [flagged]
  • coppercrisp621 hour ago
    Curious where you landed on password hashing, since zero deps in Go means you either pull x&#x2F;crypto for bcrypt&#x2F;argon2 or hand roll scrypt from stdlib. I&#x27;ve been down that road and stdlib pbkdf2 wasn&#x27;t there until recently.
  • computerfriend1 hour ago
    The readme and commit messages were written by an LLM without disclosure. I didn&#x27;t look at the code.
    • samber1 hour ago
      Do you need to disclose it when everybody do it ?<p>[EDIT] It is disclosed in contributors