Re: [RFC] Timing attack safe string comparison function
| From: | Mateusz Kocielski | Date: | Fri, 27 Dec 2013 09:04:07 +0000 |
| Subject: | Re: [RFC] Timing attack safe string comparison function | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70877@lists.php.net to get a copy of this message | ||
On Mon, Dec 23, 2013 at 07:59:57PM -0800, Jake A. Smith wrote:
> > "strcmp_secure()" or something like this would be good, as it could be
>
> used any security sensitive string comparison.
>
> I like that. It makes sense for the function to be named for what it does, not how one hopes or
> expects it will be used.??
>
I think that "secure" suffix may be confusing (what does it mean that
this function is "secure"?), "timingsafe_strcmp" or something in that
manner would be better. It simply describes what the function does.