Re: [RFC] Timing attack safe string comparison function

From: Date: Tue, 24 Dec 2013 03:59:57 +0000
Subject: Re: [RFC] Timing attack safe string comparison function
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-70868@lists.php.net to get a copy of this message
Hi all, > "strcmp_secure()" or something like this would be good, as it could be used any security sensitive string comparison. I like that. It makes sense for the function to be named for what it does, not how one hopes or expects it will be used.  JS — ​Jake A. Smith@jakeasmith | theman@jakeasmith.com — Sent from Mailbox for iPhone On Mon, Dec 23, 2013 at 4:31 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > Hi all, > On Mon, Dec 23, 2013 at 7:03 PM, Joe Watkins <krakjoe@php.net> wrote: >> I'm glad you read it as you did, I was kinda thinking out loud, >> where I ended was my final conclusion that it may be worth while as a >> complimentary tool in the hashing toolbox, and I'd prefer its name to >> reflect that. > I agree. It would be better named explicitly. > "strcmp_secure()" or something like this would be good, as it could be > used any security sensitive string comparison. > Regards, > -- > Yasuo Ohgaki > yohgaki@ohgaki.net

« previous php.internals (#70868) next »