Re: [RFC] Timing attack safe string comparison function

From: Date: Fri, 27 Dec 2013 14:03:14 +0000
Subject: Re: [RFC] Timing attack safe string comparison function
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-70881@lists.php.net to get a copy of this message
>> It might belong in ext/hash, not sure ... > > Since the function has no dependencies I'd like it to be available without extensions. > However that's not a battle I'm willing to die for. > There's an easy fix for that. Don't make hash optional. It's got no external dependencies, and despite appearances (covering many files), is actually pretty lightweight. When the extension was first bundled (years ago) a lot of the algorithm implementations were new, and all the code in the wild was using standard's md5()/sha1(), but that's shifted. -Sara

« previous php.internals (#70881) next »