Re: [VOTE] Timing attack safe string comparison function
| From: | Andrea Faulds | Date: | Mon, 03 Feb 2014 12:23:53 +0000 |
| Subject: | Re: [VOTE] Timing attack safe string comparison function | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72084@lists.php.net to get a copy of this message | ||
On 02/02/14 22:50, Rouven Weßling wrote:
as I've received no further feedback I've opened the voting on "Timing attack safe string comparison function":I've voted yes. However, at the risk of opening more bikeshedding again, I should say that I don't think hash_compare is an appropriate name. It's a timing attack-safe string comparison function, so I think something like str_equals_time_constant might be better as it is not so much a hash comparison function as a string comparison function. -- Andrea Faulds http://ajf.me/