Re: [RFC] Timing attack safe string comparison function
| From: | Sara Golemon | Date: | Fri, 27 Dec 2013 14:03:14 +0000 |
| Subject: | Re: [RFC] Timing attack safe string comparison function | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70881@lists.php.net to get a copy of this message | ||
>> It might belong in ext/hash, not sure ...
>
> Since the function has no dependencies I'd like it to be available without extensions.
> However that's not a battle I'm willing to die for.
>
There's an easy fix for that. Don't make hash optional. It's got no
external dependencies, and despite appearances (covering many files),
is actually pretty lightweight.
When the extension was first bundled (years ago) a lot of the
algorithm implementations were new, and all the code in the wild was
using standard's md5()/sha1(), but that's shifted.
-Sara