Doc #68328 [Com]: hash_equals does not mention that a difference in str length will leak

From: Date: Thu, 30 Oct 2014 09:26:34 +0000
Subject: Doc #68328 [Com]: hash_equals does not mention that a difference in str length will leak
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11595@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68328&edit=1 ID: 68328 Comment by: mikemike@php.net Reported by: asphp at dsgml dot com Summary: hash_equals does not mention that a difference in str length will leak Status: Open Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant Block user comment: N Private report: N New Comment: There is already a note present, which reads: -- Note: Both arguments must be of the same length to be compared successfully. When arguments of differing length are supplied, FALSE is returned and the length of the known string may be leaked in case of a timing attack. -- Can you supply an instance where returning false is an issue? Previous Comments: ------------------------------------------------------------------------ [2014-10-30 07:27:50] asphp at dsgml dot com Description: ------------ --- From manual page: http://www.php.net/function.hash-equals --- You should document that hash_equals will immediately return false if the strings differ in length. It doesn't even try to compare the strings up to whichever is shorter. It just returns false right away. In some applications this is a problem, so it should be documented. Note: See also Bug #67939 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68328&edit=1

« previous php.doc.bugs (#11595) next »