Re: Re: [RFC] Timing attack safe string comparison function
| From: | Yasuo Ohgaki | Date: | Mon, 23 Dec 2013 09:45:50 +0000 |
| Subject: | Re: Re: [RFC] Timing attack safe string comparison function | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70850@lists.php.net to get a copy of this message | ||
Hi Joe,
On Mon, Dec 23, 2013 at 6:09 PM, Joe Watkins <krakjoe@php.net> wrote:
> It might have more traction if the function were named
> password_compare or hash_compare or something similar that gives everyone
> the idea that it is not simply a string comparison function but the correct
> way to verify in particular passwords/hashes or whatever. I'd be much more
> inclined to say that's a good idea, providing a full set of tools for
> password related foo.
Good name would help for sure.
+1
Since this is new function independent from any other feature and could use
fix
vulnerability in user code, it would be better if we add this to 5.5.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net