Skip to content

nexhash v1.0

Latest

Choose a tag to compare

@amnottdevv amnottdevv released this 30 Aug 13:55
· 20 commits to main since this release
be9d314

Release Date: August 30, 2026

We are pleased to announce the general availability of NexHash 1.0.0. This is the first stable release of the multi-engine hashing CLI, designed for password management, file integrity verification, and keyed-message authentication.

NexHash combines industry-standard algorithms with custom high-security constructs, all in a single statically linked binary with zero runtime dependencies.


Overview

NexHash provides a unified interface for eight distinct hashing engines, each optimized for specific use cases (passwords, files, and messages). The tool supports cryptographic verification, streaming file hashing, and server-side pepper integration, making it suitable for both development environments and production deployments.


Key Features

  • Multi-Engine Architecture: Choose from 8 hashing engines, including Argon2id, bcrypt, and six custom NexHash engines.
  • Three Security Levels: Each engine supports tunable security levels (1–3) to balance performance and protection.
  • Password Hashing: Secure password storage and verification with memory-hard and computationally intensive algorithms.
  • Streaming File Hashing: Hash large files efficiently without loading them entirely into memory.
  • Keyed Message Authentication: Generate authentication tags for messages using a secret password (HMAC-style with extended expansion).
  • Password Strength Checking: Built-in entropy and strength estimation for user passwords.
  • Pepper Support: Optional server-side secret (NEXHASH_PEPPER) can be applied at runtime via environment variable—never compiled into the binary.
  • Cross-Platform: Fully compatible with Linux, macOS, and Windows (MSYS2 MinGW).
  • Static Linking: All cryptographic dependencies (Argon2, bcrypt) are vendored and statically linked. No external libraries are required at runtime.

Supported Engines

Engine Output Length Type Algorithm
argon2 43 chars passwd Argon2id (RFC 9106, memory-hard)
bcrypt 53 chars passwd bcrypt ($2b$)
nex3ph1 432 chars passwd PBKDF2-style + HKDF-expand (SHA-512)
nex4px1 1240 chars passwd PBKDF2-style + HKDF-expand (SHA mixed)
nex3fh1 256 chars file Streaming SHA-512 + iterations + HKDF
nex4px2 8743 chars passwd PBKDF2-style + HKDF-expand (SHA mixed)
nex4mx1 2048 chars message Interleaved P+T + PBKDF2 + HKDF
nex5mx1 16384 chars message Interleaved P+T + Argon2id + SHA + HKDF

Platforms & System Requirements

  • Linux: GCC or Clang, Make
  • macOS: Clang, Make
  • Windows: MSYS2 MinGW 64-bit, mingw32-make

No additional cryptographic libraries are required. The binary runs on x86_64 architectures.


Installation & Build

Building from Source

# Linux / macOS
make

# Windows (MSYS2 MinGW 64-bit)
mingw32-make

Basic Usage Examples

# Hash a password
./dist/nexhash --encode --engine argon2 --level 2 --password "secret"

# Verify a password
./dist/nexhash --decode --crypt "<hash>" --password "secret"

# Hash a file
./dist/nexhash --hash-file --file document.pdf --level 2

# Keyed message authentication
./dist/nexhash --encode --engine nex5mx1 --level 2 \
  --password "secret" --text "message"

# Check password strength
./dist/nexhash --check-strength --password "MyP@ssw0rd"

# List all engines
./dist/nexhash --list-engines

Refer to the full documentation for detailed command-line options and configuration.


Security Compliance

  • Argon2id: Implemented per RFC 9106, providing resistance against GPU-based and side-channel attacks.
  • bcrypt: Standard $2b$ variant, widely adopted for legacy compatibility.
  • Custom Engines: Designed with iterative PBKDF2, HKDF-expand, SHA-512, and interleaving techniques to mitigate brute-force and length-extension attacks.
  • Pepper: The NEXHASH_PEPPER environment variable allows for an additional server-side secret, adding a layer of defense against database compromises.

What's New in v1.0.0

  • Initial stable release.
  • Full implementation of all eight engines with roundtrip verification.
  • Cross-platform build system (Makefile) with vendorized dependencies.
  • Comprehensive test suite (make test) covering all engines.
  • Benchmarking utility (make benchmark) for performance evaluation.
  • MkDocs-based documentation site deployed to GitHub Pages.

Known Issues & Limitations

  • This is the first major version. While all core functionality is stable, performance tuning for extreme workloads (e.g., hashing terabyte-scale files) is planned for future iterations.
  • The custom engines (nex*) are designed with strong cryptographic principles but have not undergone formal third-party audits. Users requiring FIPS or NIST validation should prioritize the argon2 and bcrypt engines.
  • Windows builds require the MSYS2 environment; native Windows SDK support is planned for a future release.

Roadmap (Future Releases)

  • Integration with Windows native toolchains (MSVC).
  • Additional engines based on SHA-3 and BLAKE3.
  • Support for configuration files to persist engine and level preferences.
  • Hardware acceleration detection for optimized Argon2 performance.

Credits & Third-Party Licenses

  • Argon2 reference implementation: CC0 / Apache 2.0
  • crypt_blowfish (bcrypt): Public domain (Solar Designer / Openwall)
  • NexHash core code: MIT License

Full license details are available in the LICENSE file included in the repository.


Getting Started

For complete installation instructions, usage guides, and architectural overview, please visit the official documentation:

➡ https://amnottdevv.github.io/nexhash/


Support & Feedback

We welcome contributions, bug reports, and feature requests from the community.


Thank you for using NexHash.
Built with a focus on security, performance, and simplicity.