Re: [VOTE] Timing attack safe string comparison function
| From: | Yasuo Ohgaki | Date: | Mon, 03 Feb 2014 01:48:35 +0000 |
| Subject: | Re: [VOTE] Timing attack safe string comparison function | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72030@lists.php.net to get a copy of this message | ||
Hi Rouven,
On Mon, Feb 3, 2014 at 7:50 AM, Rouven Weßling <me@rouvenwessling.de> wrote:
> as I've received no further feedback I've opened the voting on "Timing
> attack safe string comparison function":
>
> - https://wiki.php.net/rfc/timing_attack
>
> Voting ends on 2014/02/09 11:00PM UTC
>
> Best regards
>
Thank you for setting up vote!
Timing attack is in the wild.
This function is must have function, even for release versions. IMHO.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net