Skip to content

mitigate timing attacks by taking no shortcuts#6

Open
cowens wants to merge 1 commit intoarodland:masterfrom
cowens:patch-1
Open

mitigate timing attacks by taking no shortcuts#6
cowens wants to merge 1 commit intoarodland:masterfrom
cowens:patch-1

Conversation

@cowens
Copy link
Copy Markdown

@cowens cowens commented Dec 11, 2017

The eq operator stops comparing when it is obvious two strings aren't equal. An attacker can use this information to determine the right hash one character at a time. We can remove this information leak by using a string comparison function that uses no shortcut logic.

The eq operator stops comparing when it is obvious two strings aren't equal. An attacker can use this information to determine the right hash one character at a time.  We can remove this information leak by using a string comparison function that uses no shortcut logic.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant