Re: Re: [RFC] Timing attack safe string comparison function

From: Date: Mon, 23 Dec 2013 09:45:50 +0000
Subject: Re: Re: [RFC] Timing attack safe string comparison function
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-70850@lists.php.net to get a copy of this message
Hi Joe, On Mon, Dec 23, 2013 at 6:09 PM, Joe Watkins <krakjoe@php.net> wrote: > It might have more traction if the function were named > password_compare or hash_compare or something similar that gives everyone > the idea that it is not simply a string comparison function but the correct > way to verify in particular passwords/hashes or whatever. I'd be much more > inclined to say that's a good idea, providing a full set of tools for > password related foo. Good name would help for sure. +1 Since this is new function independent from any other feature and could use fix vulnerability in user code, it would be better if we add this to 5.5. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#70850) next »