Re: Fwd: [php-src] Constant-Time bin2hex() implementation (#909)
| From: | Leigh | Date: | Wed, 26 Nov 2014 20:52:12 +0000 |
| Subject: | Re: Fwd: [php-src] Constant-Time bin2hex() implementation (#909) | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-79203@lists.php.net to get a copy of this message | ||
I'm of the opinion, this:
On 26 November 2014 at 19:45, Anthony Ferrara <ircmaxell@gmail.com> wrote:
>
> The two mcrypt functions, IMHO **MUST** be made timing safe, no matter
> what, since they **always** deal with sensitive information.
>
Extended to any crypto functions too.
But for everything else, this:
On 26 November 2014 at 20:45, Korvin Szanto <korvinszanto@gmail.com> wrote:
> I don't like the idea of any mandatory slow down, trivial or not. This
> should be opt in.
And by opt-in, my preference would be ts_* via pecl.