Re: [RFC] Timing attack safe string comparison function

From: Date: Fri, 27 Dec 2013 19:44:21 +0000
Subject: Re: [RFC] Timing attack safe string comparison function
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-70883@lists.php.net to get a copy of this message
Hi! > There's no reason the return value has to be (or even should be) > different from normal strcmp() usage. The important aspect is that > the timing be (reasonably) constant. From what I have seen, proposed solution (with XORs) can not deliver the same return value as strcmp, namely: Returns < 0 if str1 is less than str2; > 0 if str1 is greater than str2, and 0 if they are equal. So if we want even minimal compatibility with what strcmp does, it would be more complex algorithm - and I'm not sure it'd really be that useful since time-safe comparison would usually be performed for equality. > So while I like the elegance of adding an options field to > strcmp/strncmp(), I see it potentially making matters worse. We have more than two string comparison functions. Of course, keeping with long-standing traditions of PHP function design, we could just ignore them and say "so what, this one has two parameters, this one has three, big deal, it serves my use case" - but I think it's not a very good idea. Also, it general, it is not a very good idea to add options to a function that make it take completely different code branch with different logic, different return params, etc. Sometimes it's inevitable, but usually it's much better to make it a different function. -- Stanislav Malyshev, Software Architect SugarCRM: http://www.sugarcrm.com/ (408)454-6900 ext. 227

« previous php.internals (#70883) next »