Re: [VOTE] Timing attack safe string comparison function
| From: | Joe Watkins | Date: | Mon, 03 Feb 2014 07:07:09 +0000 |
| Subject: | Re: [VOTE] Timing attack safe string comparison function | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72044@lists.php.net to get a copy of this message | ||
On 02/02/2014 10:50 PM, Rouven Weßling wrote:
Hi internals, as I've received no further feedback I've opened the voting on "Timing attack safe string comparison function": - https://wiki.php.net/rfc/timing_attack Voting ends on 2014/02/09 11:00PM UTC Best regards Rouven Morning Rouven,I'd like to see more tests with this, I see you have the functionality covered, but not error conditions for arguments and no nulls ... it's pretty common for someone to pass a variable to a function expecting it to be a string but it is infact typeof null, so maybe include that in your tests just for completeness. Other than that ... nice :) Cheers Joe