Insecure hashing#
Codeaudit checks the use of insecure hashing functions.
The Python library hashlib is great. But using insecure hashing algorithms is still possible and should be avoided!
So CodeAudit performs a check on usage of the insecure hash algorithms:
md5
sha1
All hashlib constructors take a keyword-only argument
usedforsecuritywith default value True. A false value allows the use of insecure and blocked hashing algorithms in restricted environments. False indicates that the hashing algorithm is not used in a security context, e.g. as a non-cryptographic one-way compression function.
Danger
Unless there is a very good reason to still use md5 or sha1, which is almost impossible, you should demand a fix. Or if you are the developer of the code make the fix.