Re: [RFC] Timing attack safe string comparison function
| From: | Andrea Faulds | Date: | Sat, 28 Dec 2013 01:41:10 +0000 |
| Subject: | Re: [RFC] Timing attack safe string comparison function | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70891@lists.php.net to get a copy of this message | ||
On 28/12/13 00:39, Yasuo Ohgaki wrote:
On Sat, Dec 28, 2013 at 9:02 AM, Jake A. Smith <theman@jakeasmith.com>wrote:I'd suggest str_equals_constant_time(), or maybe streq_constant_time(). That name is a bit long for my tastes, though. streq_const_time()? -- Andrea Faulds http://ajf.me/Rather than str_compare_constant_time() would it be better to call it strcmp_constant_time() to keep things consistent?Since strcmp() returns 0 for equal, it might be better not to name strcmp_something() even though I proposed strcmp_secure() at first.