4 comments
Nothing to see here IMO. A large amount of code piled together in a month.<p>The push here is “zero deps”, though at that point I might as well have Claude do it like they’ve presumable done. FWIW I’m quite ok with bringing in a well-tested/maintained dep. Hand-rolling everything down to crypto primitives like is done here isn’t an advantage.
Also, a quickly vibecoded project doing something important to security, to be used by other applications, seems like a perfect way to drop a malicious backdoor (and maybe even provides the author plausible deniability when it’s found)
[flagged]
[flagged]
Curious where you landed on password hashing, since zero deps in Go means you either pull x/crypto for bcrypt/argon2 or hand roll scrypt from stdlib. I've been down that road and stdlib pbkdf2 wasn't there until recently.
The readme and commit messages were written by an LLM without disclosure. I didn't look at the code.