Doc #69230 [Asn->Csd]: password_verify should indicate whether it's vulnerable to timing attacks

From: Date: Thu, 25 Jun 2015 11:30:32 +0000
Subject: Doc #69230 [Asn->Csd]: password_verify should indicate whether it's vulnerable to timing attacks
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-12473@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69230&edit=1 ID: 69230 Updated by: peehaa@php.net Reported by: brian at access9 dot net Summary: password_verify should indicate whether it's vulnerable to timing attacks -Status: Assigned +Status: Closed Type: Documentation Problem Package: Documentation problem PHP Version: 5.5.22 Assigned To: peehaa Block user comment: N Private report: N New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2015-03-12 15:00:10] brian at access9 dot net Description: ------------ --- From manual page: http://www.php.net/function.password-verify --- The documentation for the hash_verify() function (http://php.net/manual/en/function.hash-equals.php) clearly states that it is a "Timing attack safe string comparison". The documentation for password_verify() should indicate whether it is or is not vulnerable to timing based attacks. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69230&edit=1

« previous php.doc.bugs (#12473) next »