Re: little request :)

From: Date: Thu, 06 Feb 2014 04:53:29 +0000
Subject: Re: little request :)
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-72317@lists.php.net to get a copy of this message
Hi all, I've posted the same mail in different thread. hash_compare() may only compare hashed values as the function name imply. If length differs, it may return FALSE simply. (As well as wrong type) This way, we don't have to worry about length leak and constant operation. Hash string length is not a secret. If user have 'raw data' (e.g. raw password, etc) to compare, make them apply hash function first. This achieves constant comparison (result |= *known++ ^ *user++;) and gets rid of length leak issue. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#72317) next »