Re: [RFC] Timing attack safe string comparison function
| From: | Yasuo Ohgaki | Date: | Mon, 23 Dec 2013 22:30:36 +0000 |
| Subject: | Re: [RFC] Timing attack safe string comparison function | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70866@lists.php.net to get a copy of this message | ||
Hi all,
On Mon, Dec 23, 2013 at 7:03 PM, Joe Watkins <krakjoe@php.net> wrote:
> I'm glad you read it as you did, I was kinda thinking out loud,
> where I ended was my final conclusion that it may be worth while as a
> complimentary tool in the hashing toolbox, and I'd prefer its name to
> reflect that.
I agree. It would be better named explicitly.
"strcmp_secure()" or something like this would be good, as it could be
used any security sensitive string comparison.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net