
Security News
MCP Community Begins Work on Official MCP Metaregistry
The MCP community is launching an official registry to standardize AI tool discovery and let agents dynamically find and install MCP servers.
The blakejs npm package provides JavaScript implementations of the BLAKE2b and BLAKE2s cryptographic hash functions. These hash functions are designed to be faster than MD5, SHA-1, and SHA-2, while providing a higher level of security. The package is useful for generating cryptographic hashes for data integrity, digital signatures, and other security-related applications.
BLAKE2b Hashing
This feature allows you to generate a BLAKE2b hash of a given input string. The example code demonstrates how to hash the string 'Hello, world!' and output the resulting hash in hexadecimal format.
const blake = require('blakejs');
const hash = blake.blake2bHex('Hello, world!');
console.log(hash);
BLAKE2s Hashing
This feature allows you to generate a BLAKE2s hash of a given input string. The example code demonstrates how to hash the string 'Hello, world!' and output the resulting hash in hexadecimal format.
const blake = require('blakejs');
const hash = blake.blake2sHex('Hello, world!');
console.log(hash);
Keyed Hashing
This feature allows you to generate a keyed BLAKE2b hash, which can be used for message authentication. The example code demonstrates how to hash the string 'Hello, world!' with a given key and output the resulting hash in hexadecimal format.
const blake = require('blakejs');
const key = new Uint8Array(32); // Example key
const hash = blake.blake2bHex('Hello, world!', key);
console.log(hash);
crypto-js is a widely-used library that provides a variety of cryptographic algorithms, including MD5, SHA-1, SHA-256, and more. While it does not include BLAKE2b or BLAKE2s, it offers a broader range of cryptographic functions compared to blakejs.
hash.js is a library that provides various hash functions, including SHA family algorithms. It does not support BLAKE2b or BLAKE2s, but it is known for its performance and ease of use in hashing operations.
blake2 is another npm package that provides implementations of the BLAKE2b and BLAKE2s hash functions. It is similar to blakejs but may have different performance characteristics and API design.
blakejs is a pure Javascript implementation of the BLAKE2b and BLAKE2s hash functions.
RFC 7693: The BLAKE Cryptographic Hash and MAC
BLAKE is the default family of hash functions in the venerable NaCl crypto library. Like SHA2 and SHA3 but unlike MD5 and SHA1, BLAKE offers solid security. With an optimized assembly implementation, BLAKE can be faster than all of those other hash functions.
Of course, this implementation is in Javascript, so it won't be winning any speed records. More under Performance below. It's short and sweet, less than 500 LOC.
As far as I know, this package is the easiest way to compute Blake2 in the browser.
Other options to consider:
$ npm install --save blakejs
var blake = require('blakejs')
console.log(blake.blake2bHex('abc'))
// prints ba80a53f981c4d0d6a2797b69f12f6e94c212f14685ac4b74b12bb6fdbffa2d17d87c5392aab792dc252d5de4533cc9518d38aa8dbf1925ab92386edd4009923
console.log(blake.blake2sHex('abc'))
// prints 508c5e8c327c14e2e1a72ba34eeb452f37458b209ed63a294d999b4c86675982
blake2b
to compute a BLAKE2b hashPass it a string, Buffer
, or Uint8Array
containing bytes to hash, and it will return a Uint8Array
containing the hash.
// Computes the BLAKE2B hash of a string or byte array, and returns a Uint8Array
//
// Returns a n-byte Uint8Array
//
// Parameters:
// - input - the input bytes, as a string, Buffer, or Uint8Array
// Strings are converted to UTF8 bytes
// - key - optional key Uint8Array, up to 64 bytes
// - outlen - optional output length in bytes, default 64
function blake2b(input, key, outlen) {
[...]
}
For convenience, blake2bHex
takes the same arguments and works the same way, but returns a hex string.
blake2b[Init,Update,Final]
to compute a streaming hashvar KEY = null // optional key
var OUTPUT_LENGTH = 64 // bytes
var context = blake2bInit(OUTPUT_LENGTH, KEY)
...
// each time you get a byte array from the stream:
blake2bUpdate(context, bytes)
...
// finally, once the stream has been exhausted
var hash = blake2bFinal(context)
// returns a 64-byte hash, as a Uint8Array
blake2b*
functions have blake2s*
equivalentsBLAKE2b: blake2b
, blake2bHex
, blake2bInit
, blake2bUpdate
, and blake2bFinal
BLAKE2s: blake2s
, blake2sHex
, blake2sInit
, blake2sUpdate
, and blake2sFinal
The inputs are identical except that maximum key size and maximum output size are 32 bytes instead of 64.
Can only handle up to 2**53 bytes of input
If your webapp is hashing more than 8 petabytes, you may have other problems :)
BLAKE2b: 15.2 MB / second on a 2.2GHz i7-4770HQ
BLAKE2s: 20.4 MB / second
¯\_(ツ)_/¯
If you're using BLAKE2b in server side node.js code, you probably want the native wrapper which should be able to do several hundred MB / second on the same processor.
If you're using BLAKE2b in a web app, 15 MB/sec might be fine.
Javascript doesn't have 64-bit integers, and BLAKE2b is a 64-bit integer algorithm. Writing it withUint32Array
is not that fast. BLAKE2s is a 32-bit algorithm, so it's a bit faster.
If we want better machine code at the expense of gross-looking Javascript, we could use asm.js
Creative Commons CC0. Ported from the reference C implementation in RFC 7693.
FAQs
Pure Javascript implementation of the BLAKE2b and BLAKE2s hash functions
The npm package blakejs receives a total of 570,435 weekly downloads. As such, blakejs popularity was classified as popular.
We found that blakejs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
The MCP community is launching an official registry to standardize AI tool discovery and let agents dynamically find and install MCP servers.
Research
Security News
Socket uncovers an npm Trojan stealing crypto wallets and BullX credentials via obfuscated code and Telegram exfiltration.
Research
Security News
Malicious npm packages posing as developer tools target macOS Cursor IDE users, stealing credentials and modifying files to gain persistent backdoor access.