4 comments

  • LVB 55 minutes ago
    Nothing to see here IMO. A large amount of code piled together in a month.

    The push here is “zero deps”, though at that point I might as well have Claude do it like they’ve presumable done. FWIW I’m quite ok with bringing in a well-tested/maintained dep. Hand-rolling everything down to crypto primitives like is done here isn’t an advantage.

    • dwroberts 46 minutes ago
      Also, a quickly vibecoded project doing something important to security, to be used by other applications, seems like a perfect way to drop a malicious backdoor (and maybe even provides the author plausible deniability when it’s found)
    • natty98282 6 minutes ago
      [flagged]
  • BisratMelak 1 hour ago
    [flagged]
  • coppercrisp62 1 hour ago
    Curious where you landed on password hashing, since zero deps in Go means you either pull x/crypto for bcrypt/argon2 or hand roll scrypt from stdlib. I've been down that road and stdlib pbkdf2 wasn't there until recently.
  • computerfriend 1 hour ago
    The readme and commit messages were written by an LLM without disclosure. I didn't look at the code.
    • samber 53 minutes ago
      Do you need to disclose it when everybody do it ?

      [EDIT] It is disclosed in contributors