Re: [RFC] Timing attack safe string comparison function
| From: | Pierre Joye | Date: | Fri, 27 Dec 2013 09:07:38 +0000 |
| Subject: | Re: [RFC] Timing attack safe string comparison function | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70878@lists.php.net to get a copy of this message | ||
On Dec 27, 2013 4:04 PM, "Mateusz Kocielski" <shm@digitalsun.pl> wrote:
> I think that "secure" suffix may be confusing (what does it mean that
> this function is "secure"?),
Agreed.
> "timingsafe_strcmp" or something in that
> manner would be better. It simply describes what the function does.
Can we not simply use an extra argument?
Cheers,
Pierre