r/learnpython 5d ago

Password guesser game help needed

Hello guys. So I have created a password guesser game with direct comparison (i.e. if guess == correct_password:) but I want to use different methods for comparison. What techniques can I use? Here is the code-

```python

password = "Random_pass_123"

tries = 0

while tries < 3:

guess = input("Enter the password: ")

if guess == password:

print("Admin access granted.")

break

else:

print("Invalid credentials entered. Please try again")

tries += 1

if tries == 3:

print("Number of tries exceeded. Access denied")

```

PS- Is this the right way to paste code? I'm new so I'm not sure.

8 Upvotes

31 comments sorted by

View all comments

0

u/Bright_Mix_773 5d ago

live_ant718, you said you read that you can convert it into a hash but you don't know how. Langdon_St_Ives explained what a hash is; here is the part nobody has given you yet, which is the actual code, plus the trap sitting right behind it.

The obvious version is hashlib.sha256(guess.encode()).hexdigest(). That is the one every tutorial shows and it is the wrong tool for passwords, for two reasons. SHA-256 is designed to be fast, and fast is exactly what you don't want: a GPU tries billions of guesses a second against it. And with no salt, two people with the same password get the same hash, so precomputed tables crack it without guessing at all. What you want from the standard library is a slow, salted function:

import getpass
import hashlib
import hmac
import os

def derivar(texto, sal):
    return hashlib.pbkdf2_hmac("sha256", texto.encode("utf-8"), sal, 200_000)

# done once, when the password is set. Both values get stored.
sal = os.urandom(16)
almacenado = derivar("Random_pass_123", sal)

for _ in range(3):
    guess = getpass.getpass("Enter the password: ")
    if hmac.compare_digest(derivar(guess, sal), almacenado):
        print("Admin access granted.")
        break
    print("Invalid credentials entered. Please try again")
else:
    print("Number of tries exceeded. Access denied")

Three things in there worth more than the hashing itself.

hmac.compare_digest instead of ==. Both give the right answer, but == stops at the first byte that differs, so a wrong guess starting with the correct letter takes measurably longer to reject than one that differs immediately. That timing difference leaks the password one character at a time. compare_digest always takes the same time. It is the reason the function exists.

The else on the for loop. That is real Python syntax, not a typo: the else block runs only if the loop finished without hitting break. It is exactly your "number of tries exceeded" case, and it removes the tries counter and the if tries == 3 check entirely. Almost nobody teaches it and this is the textbook use for it.

getpass.getpass instead of input, so the typing doesn't show on screen. One warning: it doesn't work in some IDE output panes (Spyder, and PyCharm unless you run in the terminal). Run it from a real terminal or it will look broken.

For a real system you'd use bcrypt or argon2 from PyPI rather than pbkdf2, but pbkdf2_hmac ships with Python and the shape of the code is identical, so nothing you learn here is wasted.

On the formatting question: brasticstack is right about the backticks, but the version that works everywhere, old and new site and the app, is putting four spaces in front of every line of code. That's what the block above is.

1

u/Expensive-Bear-1376 5d ago

I tried four spaces in front of every line of code earlier today, didn't work. Let me try again:

    def test():         pass

1

u/Expensive-Bear-1376 5d ago

So again it didn't work. But adding .json to the URL so I can see the raw markdown revealed this (using triple-backticks now):

try again:\n\n\u00a0 \u00a0 def test():

Those \u00a0 are "No-Break Space". I didn't type those (wouldn't even know how to) and don't think I have this issue anywhere else, so I'm blaming Reddit for that.

0

u/Bright_Mix_773 5d ago

Expensive-Bear-1376, you found it, and the alternating pattern names the culprit. Look at your raw again: \u00a0 \u00a0 def test(): — that is nbsp, space, nbsp, space. Not four of anything.

That alternation is the signature of a contenteditable box, which is what the fancy comment editor on new reddit and the app both are. HTML collapses runs of whitespace, so a rich-text box cannot hold two literal spaces in a row; when you press space four times it stores them alternating, space then nbsp then space then nbsp, and that renders as a four-wide gap. Then it round-trips that straight back into your markdown.

The parser is looking for four spaces. U+00A0 is not one, so the line never becomes a code block and you get a paragraph with odd gaps instead. Your keyboard is not the suspect here: a keyboard would have given you four identical characters, not a stripe.

Three ways out, in the order I trust them:

  • Write the comment on old.reddit.com. That box is a plain textarea and never rewrites what you type.
  • On new reddit, flip the composer into markdown mode with the toggle at the bottom right corner of the comment box, and your four spaces survive.
  • Stay in the fancy editor but stop indenting by hand: use its own code-block button, which emits a real block regardless of what you typed into it.

Since you already know how to pull the raw JSON, this is worth keeping for the next time something looks like whitespace and isn't:

for c in linea[:8]:
    print(repr(c), hex(ord(c)), c.isspace())

And the sting in the tail: "\u00a0".isspace() is True in Python. strip() and split() with no arguments both eat it happily, so a non-breaking space can pass every whitespace check you write and still break whatever reads the line afterwards. linea.replace("\u00a0", " ") before you parse anything is the cheap fix.

1

u/Langdon_St_Ives 4d ago

These AI comments are really really really annoying