How HN: Go-dev-auth zero-dependency authentication library for Go

12 pointsposted 8 hours ago
by BisratMelak

9 Comments

LVB

7 hours ago

Nothing to see here IMO. A large amount of code piled together in a month.

The push here is “zero deps”, though at that point I might as well have Claude do it like they’ve presumable done. FWIW I’m quite ok with bringing in a well-tested/maintained dep. Hand-rolling everything down to crypto primitives like is done here isn’t an advantage.

dwroberts

7 hours ago

Also, a quickly vibecoded project doing something important to security, to be used by other applications, seems like a perfect way to drop a malicious backdoor (and maybe even provides the author plausible deniability when it’s found)

coppercrisp62

8 hours ago

Curious where you landed on password hashing, since zero deps in Go means you either pull x/crypto for bcrypt/argon2 or hand roll scrypt from stdlib. I've been down that road and stdlib pbkdf2 wasn't there until recently.

computerfriend

8 hours ago

The readme and commit messages were written by an LLM without disclosure. I didn't look at the code.

samber

7 hours ago

Do you need to disclose it when everybody do it ?

[EDIT] It is disclosed in contributors