Re: Fwd: [php-src] Constant-Time bin2hex() implementation (#909)
| From: | Korvin Szanto | Date: | Wed, 26 Nov 2014 20:45:02 +0000 |
| Subject: | Re: Fwd: [php-src] Constant-Time bin2hex() implementation (#909) | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-79201@lists.php.net to get a copy of this message | ||
I don't like the idea of any mandatory slow down, trivial or not. This
should be opt in.
On Wed, Nov 26, 2014, 12:28 PM Rasmus Lerdorf <rasmus@lerdorf.com> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On 11/26/2014 11:45 AM, Anthony Ferrara wrote:
> >> That seems like a lot of functions to artificially slow down.
> >
> > Well, in most cases it shouldn't slow it down by a non-trivial
> > margin.
>
> If that can be shown definitively, then I would have fewer objections.
> I still worry that it will take some time to get it right and the
> number of security bug reports we would need to deal with against core
> php functions as various security people find info leaks in the
> implementations. That's where having it in a pecl extension initially
> helps because we can react quicker and push out new releases of the
> extension than if we have to release a new version of PHP each time.
>
> - -Rasmus
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1
>
> iEYEARECAAYFAlR2N6MACgkQlxayKTuqOuBP5QCdHwQMN9BOz6MruWiL3Rt9AGVP
> hU8AnAx4TehiGHbEU+zDdlAg0Y8qnAaw
> =ZbfE
> -----END PGP SIGNATURE-----
>
> --
> PHP Internals - PHP Runtime Development Mailing List
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>